THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qr67-gv47-xwwh (medium) — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

[GHSA] GHSA-qr67-gv47-xwwh (medium) — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

medgithub_advisoriesPublished 2026-08-26

GHSA-qr67-gv47-xwwh Severity: medium CVE: CVE-2026-54590

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The 2.23.0 guard that sanitises the SSH username before `%u` substitution in `AuthorizedKeysFile` block

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qr67-gv47-xwwh