« All posts

Insecure Argument Handling in Tailscale SSH Allowed Root Access

A vulnerability in Tailscale SSH allowed root access via usernames with a leading '-'. Upgrade recommended.

Tailscale SSH previously accepted usernames with a leading '-' character, allowing attackers to gain root access. This vulnerability has been addressed by rejecting such usernames. Users are advised to upgrade to Tailscale version 1.98.9 or newer to mitigate this risk.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work