AsyncSSH: SCP Path Traversal to Arbitrary File Write
Published Jul 8, 2026
8.1
HIGHCVSS 3.1
EPSS 0.49%
Description
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ traversal sequences because _parse_cd_args in scp.py returns server-provided names verbatim and _recv_files joins them to the destination path without enforcing the target directory boundary. This issue is fixed in version 2.23.1.
Affected products
-
- Version < 2.23.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This Important flaw in AsyncSSH's SCP client allows a malicious SSH server to perform arbitrary file writes on the client's filesystem through directory traversal. This occurs when an AsyncSSH SCP client connects to a compromised or malicious server, enabling unauthorized data modification or system disruption on the client.
Red Hat mitigation
The core risk of this flaw is that the malicious server uses a path traversal trick to write files where it shouldn't on your client (like overwriting /etc/shadow or critical system binaries). By making the container's root filesystem read-only, you completely neutralize this attack. Even if the vulnerability is triggered, the container's kernel will block the unauthorized write attempt.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 9, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.49% (0.00492) | 40.13th | v5 (v2026.06.15) |
| Jul 9, 2026 | 0.32% (0.00317) | 23.61th | v5 (v2026.06.15) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-54591 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2498244 Issue Tracking
- https://github.com/advisories/GHSA-2wxc-x7rj-hg8f Advisory
- https://github.com/ronf/asyncssh/commit/d730803b8e4e94c20c7580d90f94d1e05f9f58de x_refsource_MISC
- https://github.com/ronf/asyncssh/releases/tag/v2.23.1 x_refsource_MISC
- https://github.com/ronf/asyncssh/security/advisories/GHSA-2wxc-x7rj-hg8f x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-54591
- https://www.cve.org/CVERecord?id=CVE-2026-54591
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-54591 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2498244 | Issue Tracking | |
| https://github.com/advisories/GHSA-2wxc-x7rj-hg8f | Advisory | |
| https://github.com/ronf/asyncssh/commit/d730803b8e4e94c20c7580d90f94d1e05f9f58de | x_refsource_MISC | |
| https://github.com/ronf/asyncssh/releases/tag/v2.23.1 | x_refsource_MISC | |
| https://github.com/ronf/asyncssh/security/advisories/GHSA-2wxc-x7rj-hg8f | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54591 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-54591 |
Change history (0)
No recorded changes yet.