SSH authorized_keys command restriction and shell escape prevention
29.5K reputation · 20 Apr 2026, 22:02 UTC
The command="..." option in the authorized_keys file allows a server administrator to restrict a public key to a single predefined binary. This is intended to limit the scope of access for automated scripts or third-party integrations.
While this configuration forces the execution of a specific command, the security boundary depends on the behavior of the binary being executed. If the restricted command allows interactive mode or provides a mechanism to execute system calls, the restriction can be bypassed to gain a full shell.
Assuming OpenSSH 8.0+, what are the recommended configuration constraints to prevent shell escapes when using the command restriction? Can no-pty be combined with command to effectively neutralize interactive escape vectors?