Path Traversal Vulnerability in Wish SSH Server by Charm Bracelets
CVE-2026-41589

9.6CRITICAL

Key Information:

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41589?

The Wish SSH server versions up to 2.0.0 are susceptible to path traversal attacks via the SCP middleware. Malicious clients can exploit this vulnerability by sending specially crafted filenames that include '../' sequences, potentially allowing them to read arbitrary files, write files, and create directories outside the intended root directory. This significant security risk has been addressed in version 2.0.1 of the product.

Affected Version(s)

wish >= 2.0.0, < 2.0.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.