UBUNTU-CVE-2026-54591
AsyncSSH versions prior to 2.23.1 contain a vulnerability in the SCP client implementation where a malicious SSH server can write arbitrary files on the client's filesystem by exploiting directory traversal sequences in filenames. This occurs because the client does not properly sanitize server-provided filenames before writing them. The issue is fixed in AsyncSSH version 2.23.1.
AI Analysis
Technical Summary
AsyncSSH is a Python package providing asynchronous SSHv2 client and server functionality. Versions before 2.23.1 have a security flaw in the SCP client where the function _parse_cd_args returns server-supplied filenames verbatim, and _recv_files joins these filenames to the destination path without enforcing directory boundaries. This allows a malicious SSH server to write files outside the intended directory by using '../' traversal sequences in filenames. The vulnerability is resolved in version 2.23.1.
Potential Impact
A malicious SSH server can exploit this vulnerability to write arbitrary files anywhere on the AsyncSSH SCP client's filesystem, potentially leading to integrity and availability impacts. This could allow overwriting critical files or placing malicious files on the client system.
Mitigation Recommendations
Upgrade AsyncSSH to version 2.23.1 or later, where this vulnerability is fixed. The affected versions listed should be considered vulnerable until updated. No other mitigations are specified.
UBUNTU-CVE-2026-54591
Description
AsyncSSH versions prior to 2.23.1 contain a vulnerability in the SCP client implementation where a malicious SSH server can write arbitrary files on the client's filesystem by exploiting directory traversal sequences in filenames. This occurs because the client does not properly sanitize server-provided filenames before writing them. The issue is fixed in AsyncSSH version 2.23.1.
CVSS v3.1
Score 8.1high
Affected software
pkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]~esm2?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
AsyncSSH is a Python package providing asynchronous SSHv2 client and server functionality. Versions before 2.23.1 have a security flaw in the SCP client where the function _parse_cd_args returns server-supplied filenames verbatim, and _recv_files joins these filenames to the destination path without enforcing directory boundaries. This allows a malicious SSH server to write files outside the intended directory by using '../' traversal sequences in filenames. The vulnerability is resolved in version 2.23.1.
Potential Impact
A malicious SSH server can exploit this vulnerability to write arbitrary files anywhere on the AsyncSSH SCP client's filesystem, potentially leading to integrity and availability impacts. This could allow overwriting critical files or placing malicious files on the client system.
Mitigation Recommendations
Upgrade AsyncSSH to version 2.23.1 or later, where this vulnerability is fixed. The affected versions listed should be considered vulnerable until updated. No other mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-54591
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b47868715ace43d982ab
Added to database: 07/16/2026, 10:37:44 UTC
Last enriched: 07/16/2026, 11:53:33 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.