CVE-2026-54590: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in ronf asyncssh
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.
AI Analysis
Technical Summary
CVE-2026-54590 is a path traversal vulnerability in the AsyncSSH Python package (version 2.23.0) where the fix for a previous vulnerability (CVE-2026-45309) was incomplete. The SSHServerConfig._set_tokens method blocks certain path elements (/, , ..) before %u substitution in AuthorizedKeysFile, but does not block leading ~ or environment variable expansions (${ENV}). These expansions occur later in _expand_val and Path(filename).expanduser(), allowing an attacker to escape the restricted authorized-keys directory. The vulnerability is fixed in AsyncSSH version 2.23.1.
Potential Impact
An attacker could exploit this vulnerability to bypass directory restrictions on the authorized keys file path, potentially allowing unauthorized access or modification of SSH authorized keys outside the intended directory. The CVSS score of 5.9 (medium severity) reflects the network attack vector with high complexity and no privileges required, impacting integrity but not confidentiality or availability.
Mitigation Recommendations
Upgrade AsyncSSH to version 2.23.1 or later, where this path traversal issue is fixed. No other mitigation is indicated or required as the fix addresses the vulnerability directly.
CVE-2026-54590: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in ronf asyncssh
Description
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in AuthorizedKeysFile but does not block a leading ~ or ${ENV}, allowing later expansion in _expand_val and Path(filename).expanduser() to escape the intended authorized-keys directory. This issue is fixed in version 2.23.1.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54590 is a path traversal vulnerability in the AsyncSSH Python package (version 2.23.0) where the fix for a previous vulnerability (CVE-2026-45309) was incomplete. The SSHServerConfig._set_tokens method blocks certain path elements (/, , ..) before %u substitution in AuthorizedKeysFile, but does not block leading ~ or environment variable expansions (${ENV}). These expansions occur later in _expand_val and Path(filename).expanduser(), allowing an attacker to escape the restricted authorized-keys directory. The vulnerability is fixed in AsyncSSH version 2.23.1.
Potential Impact
An attacker could exploit this vulnerability to bypass directory restrictions on the authorized keys file path, potentially allowing unauthorized access or modification of SSH authorized keys outside the intended directory. The CVSS score of 5.9 (medium severity) reflects the network attack vector with high complexity and no privileges required, impacting integrity but not confidentiality or availability.
Mitigation Recommendations
Upgrade AsyncSSH to version 2.23.1 or later, where this path traversal issue is fixed. No other mitigation is indicated or required as the fix addresses the vulnerability directly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T19:45:23.538Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4eb690c9d9e3dbe3b68725
Added to database: 07/08/2026, 20:44:00 UTC
Last enriched: 07/16/2026, 09:53:39 UTC
Last updated: 08/23/2026, 10:52:09 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.