PT-2026-55839 · Kas · Kas
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
kas versions prior to 5.4
Description
Internal SSH key setup triggered by
SSH PRIVATE KEY or SSH PRIVATE KEY FILE creates a ~/.ssh/config file when no user-specific SSH configuration exists. The ssh no host key check() function in kas/libcmds.py adds a global Host * rule with StrictHostKeyChecking no without checking ctx.managed env. This causes the setting to persist after the tool exits, affecting future SSH sessions for the local user. Consequently, subsequent SSH connections may accept attacker-controlled host keys without verification, increasing the risk of a man-in-the-middle attack, which is an attack where a malicious actor intercepts communication between two parties to steal or manipulate data.Recommendations
Update to version 5.4.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kas