Path Traversal Vulnerability in Wish SSH Server by Charm Bracelets
CVE-2026-41589
9.6CRITICAL
What is CVE-2026-41589?
The Wish SSH server versions up to 2.0.0 are susceptible to path traversal attacks via the SCP middleware. Malicious clients can exploit this vulnerability by sending specially crafted filenames that include '../' sequences, potentially allowing them to read arbitrary files, write files, and create directories outside the intended root directory. This significant security risk has been addressed in version 2.0.1 of the product.
Affected Version(s)
wish >= 2.0.0, < 2.0.1
