Path traversal in AsyncSSH - CVE-2026-54591

 

Path traversal in AsyncSSH - CVE-2026-54591

Published: October 5, 2026


Vulnerability identifier: #VU153257
CSH Severity: High
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54591
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files.

The vulnerability exists due to path traversal in the SCP receive path when processing server-provided filenames during SCP downloads. A remote attacker can send SCP filenames containing traversal sequences to overwrite arbitrary files.

User interaction is required to initiate an SCP download from the malicious server.


Affected software

AsyncSSH
Fedora
python-asyncssh

How to mitigate CVE-2026-54591

Install security update from vendor's website.

AsyncSSH - update to 2.23.1
python-asyncssh - addressed in versions 2.23.1-1.fc43, 2.24.0-1.fc44, 2.24.0-2.el10_3

External References

Related Security Bulletins