Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
Authenticated chisel clients can bypass –authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client authenticates with a permitted remote, then opens channels to any host:port it wants.