Junglewise Threat Intelligence

CVE-2026-41589: Charmbracelet Wish path traversal in SCP middleware

CVE-2026-41589 · Severity: critical · CVSS 9.6 · Published 2026-05-07

Vendors: Go.

Executive brief

Wish is a library used to build custom SSH servers in Go. A security flaw in its SCP (Secure Copy) component allows users to bypass directory restrictions. An attacker with basic login access could read or write any file on the server's filesystem, potentially leading to full system takeover or the theft of sensitive data like passwords and private keys.

Technical details

A path traversal vulnerability exists in the SCP middleware of the Wish SSH server library. The root cause is located in the fileSystemHandler.prefixed() method within scp/filesystem.go, which uses filepath.Clean and filepath.Join without verifying that the resulting path remains within the designated root directory. An attacker can exploit this by providing filenames containing '../' sequences during SCP operations. This allows for three primary attack vectors: arbitrary file writes (scp -t), arbitrary file reads (scp -f), and file enumeration via globbing. Successful exploitation can lead to remote code execution if the attacker overwrites sensitive files like authorized_keys or system configuration files. The issue is fixed in version 2.0.1.

Affected products

  • Charmbracelet Wish 2.0.0 to 2.0.1

Timeline

  • 2026-04-17: patched: Version 2.0.1 released to address the vulnerability.
  • 2026-05-07: disclosed: Vulnerability publicly disclosed and CVE assigned.

References