/ Remote Code Execution in OpenSSH's forwarded ssh-agent
Agent forwarding should be enabled with caution. Users with the ability to bypass file permissions on the remote host ... can access the local agent through the forwarded connection… CVE-2023-38408:
— www.qualys.com/2023/07…gent.txt