Vulnerability Description
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ traversal sequences because _parse_cd_args in scp.py returns server-provided names verbatim and _recv_files joins them to the destination path without enforcing the target directory boundary. This issue is fixed in version 2.23.1.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/ronf/asyncssh/commit/d730803b8e4e94c20c7580d90f94d1e05f9f58de
- https://github.com/ronf/asyncssh/releases/tag/v2.23.1
- https://github.com/ronf/asyncssh/security/advisories/GHSA-2wxc-x7rj-hg8f
FAQ
What is CVE-2026-54591?
CVE-2026-54591 is a vulnerability with a CVSS score of 8.1 (HIGH). AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can w...
How severe is CVE-2026-54591?
CVE-2026-54591 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54591?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.