Junglewise Threat Intelligence

CVE-2026-54590: ronf AsyncSSH path traversal in AuthorizedKeysFile username substitution

CVE-2026-54590 · Severity: medium · CVSS 5.9 · Published 2026-07-08

Technologies: asyncssh (PyPI), Ron Fredericksen Asyncssh. Vendors: PyPI.

Executive brief

AsyncSSH's SSH server component re-evaluates the AuthorizedKeysFile configuration during user authentication. A previous patch added a guard to block path traversal attacks via username substitution, but the guard can be bypassed using special characters like tilde (~) or environment variable expansion that are processed after the guard runs, allowing an attacker to redirect authorized-keys file lookups to arbitrary home directories and potentially gain unauthorized SSH access if a victim's authorized-keys file contains the attacker's key.

Technical details

The vulnerability is an incomplete fix for CVE-2026-45309. The original guard in SSHServerConfig._set_tokens (config.py:715-716) blocks SSH usernames containing forward slash, backslash, or equal to ".." before %u substitution in AuthorizedKeysFile. However, the substituted value is subsequently processed through environment-variable expansion and expanduser() at file-open time. The expanduser() function expands a leading tilde (~) to a user's home directory, and environment expansion can inject path separators. A username like "~root" passes the guard (no slashes), but after %u substitution and expanduser() expansion, the authorized-keys path is redirected to /root/.ssh/authorized_keys instead of the intended per-user location. The client-supplied username reaches this code path pre-authentication when _process_userauth_request reads the username from SSH_MSG_USERAUTH_REQUEST and calls reload_config() before key validation. Primary attack vector requires %u to be the leading path component in AuthorizedKeysFile; a secondary but weaker vector uses ${ENV} references to re-introduce slashes. Patch version 2.23.1 addresses this vulnerability.

Affected products

  • Ron Fredericksen asyncssh <=2.23.0

Timeline

  • 2026-06-16: disclosed: GitHub Advisory GHSA-qr67-gv47-xwwh published
  • 2026-06-16: patched: Fixed in asyncssh 2.23.1
  • 2026-08-26: advisory: Full technical advisory published

References

Related threats