PT-2026-44151 · Pypi · Asyncssh

CVE-2026-45309

·

Published

2026-05-27

·

Updated

2026-08-27

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions asyncssh versions 2.22.0 through 2.23.0
Description An issue exists during pre-authentication server configuration reload where the %u token in the AuthorizedKeysFile setting is expanded using the raw SSH username without rejecting path separators or .. segments. This allows a remote attacker to use path traversal in the username to force the server to read an authorized-keys file from a location outside the intended directory. If the attacker can reference or place a readable file in the authorized-keys format containing their public key, they can successfully authenticate over SSH as the traversal username.
Recommendations Update to version 2.23.1 or later. As a temporary workaround, ensure the application rejects usernames containing /, ``, or .. before they are processed for key-file selection.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-45309
ECHO-478B-8EC8-3DC3
GHSA-G794-3FMP-753H
OPENSUSE-SU-2026:11042-1
PYSEC-2026-2384

Affected Products

Asyncssh