HIGH 8.1 GitHub
CVE-2026-54591
asyncssh has SCP Path Traversal to Arbitrary File Write
| | |
|---|---|
| Product | asyncssh (all versions through 2.23.0) |
| Related | CVE-2019-6111 (same class in OpenSSH) |
| Fix | AsyncSSH 2.23.1 |
A malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing `../` traversal sequences. The SCP receive path does not currently sanitize server-provided filenames. By chaining directory traversals via the `D` (directory) action, an attacker can escape any target directory and overwrite `~/.b
Affected Products
- pip/asyncssh <= 2.23.0
References
- https://github.com/advisories/GHSA-2wxc-x7rj-hg8f
- https://github.com/ronf/asyncssh/security/advisories/GHSA-2wxc-x7rj-hg8f
- https://nvd.nist.gov/vuln/detail/CVE-2026-54591
- https://github.com/ronf/asyncssh/commit/d730803b8e4e94c20c7580d90f94d1e05f9f58de
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-08-26 via GitHub. Affected: pip/asyncssh <= 2.23.0.
vulnfeed aggregates 11364 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.