THREAT OPS › Threat News › [GHSA] GHSA-qr67-gv47-xwwh (medium) — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
[GHSA] GHSA-qr67-gv47-xwwh (medium) — asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
GHSA-qr67-gv47-xwwh Severity: medium CVE: CVE-2026-54590
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The 2.23.0 guard that sanitises the SSH username before `%u` substitution in `AuthorizedKeysFile` block
Indicators of compromise
- CVE-2026-45309cve
- CVE-2026-54590cve
- 203.0.113.7ipv4
Original source: https://github.com/advisories/GHSA-qr67-gv47-xwwh