Executive brief
AsyncSSH's SSH server component re-evaluates the AuthorizedKeysFile configuration during user authentication. A previous patch added a guard to block path traversal attacks via username substitution, but the guard can be bypassed using special characters like tilde (~) or environment variable expansion that are processed after the guard runs, allowing an attacker to redirect authorized-keys file lookups to arbitrary home directories and potentially gain unauthorized SSH access if a victim's authorized-keys file contains the attacker's key.
Technical details
The vulnerability is an incomplete fix for CVE-2026-45309. The original guard in SSHServerConfig._set_tokens (config.py:715-716) blocks SSH usernames containing forward slash, backslash, or equal to ".." before %u substitution in AuthorizedKeysFile. However, the substituted value is subsequently processed through environment-variable expansion and expanduser() at file-open time. The expanduser() function expands a leading tilde (~) to a user's home directory, and environment expansion can inject path separators. A username like "~root" passes the guard (no slashes), but after %u substitution and expanduser() expansion, the authorized-keys path is redirected to /root/.ssh/authorized_keys instead of the intended per-user location. The client-supplied username reaches this code path pre-authentication when _process_userauth_request reads the username from SSH_MSG_USERAUTH_REQUEST and calls reload_config() before key validation. Primary attack vector requires %u to be the leading path component in AuthorizedKeysFile; a secondary but weaker vector uses ${ENV} references to re-introduce slashes. Patch version 2.23.1 addresses this vulnerability.
Affected products
- Ron Fredericksen asyncssh <=2.23.0
Timeline
- 2026-06-16: disclosed: GitHub Advisory GHSA-qr67-gv47-xwwh published
- 2026-06-16: patched: Fixed in asyncssh 2.23.1
- 2026-08-26: advisory: Full technical advisory published