THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mv8m-v9v6-5f94 (low) — kas Persistently Disables SSH Host Key Checking

[GHSA] GHSA-mv8m-v9v6-5f94 (low) — kas Persistently Disables SSH Host Key Checking

medgithub_advisoriesPublished 2026-08-26

GHSA-mv8m-v9v6-5f94 Severity: low CVE: CVE-2026-54548

kas Persistently Disables SSH Host Key Checking

### Summary

kas persistently disables SSH host key checking for the invoking user when internal SSH key setup is triggered via `SSH_PRIVATE_KEY` or `SSH_PRIVATE_KEY_FILE` and no user-specific SSH configuration file exists so far.

When this path is used, kas creates `~/.ssh/config` with a globa

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mv8m-v9v6-5f94