ssh-gui
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecuritybin/ssh-gui
MEDIUMSecurityMEDIUM
bin/ssh-gui
The code is a legitimate SSH-based macOS GUI automation utility and shows no clear malicious payload or covert data theft. It contains two significant command-injection vulnerabilities: direct interpolation of the screenshot region and unsafe interpolation of SSH_GUI_AX_TIMEOUT into a remote shell command. The arbitrary AppleScript interface is intentionally powerful and should be restricted to trusted users. Shell-escape or validate all interpolated values, especially region and timeout, before use.
Confidence: 98%Severity: 82%
Audit Metadata