THREAT OPS › Threat News › [GHSA] GHSA-mv8m-v9v6-5f94 (low) — kas Persistently Disables SSH Host Key Checking
[GHSA] GHSA-mv8m-v9v6-5f94 (low) — kas Persistently Disables SSH Host Key Checking
GHSA-mv8m-v9v6-5f94 Severity: low CVE: CVE-2026-54548
kas Persistently Disables SSH Host Key Checking
### Summary
kas persistently disables SSH host key checking for the invoking user when internal SSH key setup is triggered via `SSH_PRIVATE_KEY` or `SSH_PRIVATE_KEY_FILE` and no user-specific SSH configuration file exists so far.
When this path is used, kas creates `~/.ssh/config` with a globa
Indicators of compromise
- CVE-2026-54548cve
Original source: https://github.com/advisories/GHSA-mv8m-v9v6-5f94