Executive brief
AsyncSSH is a Python SSH library widely used for secure remote file transfer via SCP. A malicious SSH server can exploit the SCP client to write arbitrary files anywhere on the user's filesystem by sending specially crafted directory traversal sequences (e.g., `../`). This can lead to remote code execution by overwriting shell configuration files like `~/.bashrc` or SSH authorization files, allowing attackers to execute code when the user next logs in or opens a terminal.
Technical details
This is a path traversal (CWE-22) vulnerability in AsyncSSH's SCP receive implementation. The vulnerability exists in the `_parse_cd_args()` function (scp.py:134-142) and `_recv_files()` function (scp.py:706-713), which fail to sanitize server-supplied filenames before joining them with the target directory path using `posixpath.join()`. An attacker controlling a malicious SSH server can send SCP protocol messages with filenames containing `../` sequences to escape the intended download directory. By chaining directory traversal commands via the SCP `D` (directory) action, an attacker can overwrite critical files such as `~/.bashrc`, `~/.profile`, `~/.ssh/rc`, or `~/.ssh/authorized_keys`. The vulnerability requires user interaction (the application must call `asyncssh.scp()` to download from an attacker-controlled server) and network connectivity, but no authentication or special privileges. Remote code execution is achievable when the user's next login/terminal session sources the modified files. This is the same vulnerability class as CVE-2019-6111 in OpenSSH. A patch is available in AsyncSSH version 2.23.1 and later.
Affected products
- ronf asyncssh <= 2.23.0
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched: AsyncSSH 2.23.1 released
- 2026-08-26: advisory
References
- https://api.github.com/users/Jaden-Furtado
- https://github.com/Jaden-Furtado
- https://api.github.com/users/Jaden-Furtado/gists%7B/gist_id%7D
- https://api.github.com/users/Jaden-Furtado/repos
- https://avatars.githubusercontent.com/u/136704191?v=4
- https://api.github.com/users/Jaden-Furtado/events%7B/privacy%7D