← Vulnerability feed

Vulnerability record · CVE-2022-36633 · published 24 August 2022

CVE-2022-36633: Teleport command injection via crafted SSH agent install link

Goteleport · Teleport

Teleport 9.3.6 is vulnerable to OS command injection that leads to remote code execution. An attacker can URL-encode a bash escape sequence with carriage return and line feed and place it where a token is expected in an SSH agent installation link, then deliver that link to a user through social engineering. The trusted Teleport server is used to deliver the payload, so the malicious link appears to come from a legitimate service.

8.8 CVSS 3.1 High EPSS 50% · top 1.1% CWE-78 · OS command injection
8.8CVSS 3.1 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a user in a social engineering attack. This is fully unauthenticated attack utilizing the trusted teleport server to deliver the payload.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit references and a high EPSS score, tempered only by the required user interaction.

What it is

Teleport 9.3.6 is vulnerable to OS command injection that leads to remote code execution. An attacker can URL-encode a bash escape sequence with carriage return and line feed and place it where a token is expected in an SSH agent installation link, then deliver that link to a user through social engineering. The trusted Teleport server is used to deliver the payload, so the malicious link appears to come from a legitimate service.

Impact

Successful exploitation gives the attacker arbitrary command execution in the context of the victim's installation flow, allowing code to run on the affected host. Because the payload is delivered through the trusted Teleport server, the attacker gains execution without needing valid credentials.

Attack surface

The flaw is reached over the network through a crafted SSH agent installation URL that substitutes a URL-encoded bash escape for the expected token. No authentication is required, but the attack depends on user interaction: the victim must open the malicious link, making it a social engineering vector.

Exploitation

CISA KEV does not list this CVE, but public exploit references exist on Packet Storm for Teleport 9.3.6 and 10.1.1, and EPSS gives a 30-day probability of roughly 0.50 (98.8th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Teleport to a fixed release; version 9.3.6 is explicitly named as vulnerable, so move to the vendor's patched build.
  • Treat SSH agent installation links as untrusted input and validate or sanitize the token parameter before it reaches shell execution.
  • Restrict or disable the agent installation link feature if it is not operationally required.
  • Train users not to open unsolicited SSH agent installation links, since exploitation requires them to click.
  • Monitor Teleport server logs for installation requests containing URL-encoded control characters or shell metacharacters.

Detection

  • Search Teleport and web server logs for agent installation requests whose token parameter contains %0d, %0a, or other URL-encoded shell metacharacters.
  • Alert on outbound or child process execution spawned by the Teleport agent installation flow, especially bash or sh invocations.
  • Review endpoint telemetry for command lines containing carriage return or line feed escapes originating from browser or Teleport-related processes.
  • Correlate Teleport installation link generation and access events with subsequent process creation on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36633 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41393Goteleport teleport vulnerabilityTeleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.EPSS 1.1%6.5CVE-2022-38599Goteleport teleport exposure of resource to wrong sphere vulnerabilityTeleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.EPSS 0.84%6.5CVE-2021-41395Goteleport teleport vulnerabilityTeleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations, via a crafted database name…EPSS 0.85%5.3CVE-2021-41394Goteleport teleport vulnerabilityTeleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.EPSS 1.2%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2022-36633), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.