sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92042.json"