github.com/charmbracelet/wish
Make SSH apps, just like that! 💫
Activity
- Latest release
- 1y ago
- Total releases
- 20
- Cadence
- ~35 days
- Last 12 months
- 0
Reach
- Stars
- 5.5k
Details
- First release
- Apr 05, 2022
| Version | Released | |
|---|---|---|
v1.4.7
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.7
patch
Dependencies (17)
+ 9 more |
|
v1.4.6
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.6
patch
Dependencies (17)
+ 9 more |
|
v1.4.5
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.5
patch
Dependencies (17)
+ 9 more |
|
v1.4.4
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.4
patch
Dependencies (17)
+ 9 more |
|
v1.4.3
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.3
patch
Dependencies (16)
+ 8 more |
|
v1.4.2
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.2
patch
Dependencies (17)
+ 9 more |
|
v1.4.1
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.1
patch
Dependencies (15)
+ 7 more |
|
v1.4.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.4.0
minor
Dependencies (13)
+ 5 more |
|
v1.3.2
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.3.2
patch
Dependencies (13)
+ 5 more |
|
v1.3.1
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.3.1
patch
Dependencies (13)
+ 5 more |
|
v1.3.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.3.0
minor
Dependencies (13)
+ 5 more |
|
v1.2.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.2.0
minor
Dependencies (13)
+ 5 more |
|
v1.1.1
patch
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.1.1
patch
Dependencies (13)
+ 5 more |
|
v1.1.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.1.0
minor
Dependencies (13)
+ 5 more |
|
v1.0.0
major
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v1.0.0
major
Dependencies (12)
+ 4 more |
|
v0.7.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v0.7.0
minor
Dependencies (11)
+ 3 more |
|
v0.6.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v0.6.0
minor
Dependencies (11)
+ 3 more |
|
v0.5.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v0.5.0
minor
Dependencies (11)
+ 3 more |
|
v0.4.0
minor
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v0.4.0
minor
Dependencies (11)
+ 3 more |
|
v0.3.1
initial
1 CVE
CVE-2026-41589
GHSA-xjvp-7243-rg9h
GO-2026-5762
Apr 18, 2026
Wish has SCP Path Traversal that allows arbitrary file read/write
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
SummaryThe SCP middleware in Affected Versions
DetailsRoot CauseThe
When Attack Vector 1: Arbitrary File Write (scp -t)When receiving files from a client (
The captured filename is used directly in Attack Vector 2: Arbitrary File Read (scp -f)When sending files to a client ( Attack Vector 3: File Enumeration via GlobThe Proof of ConceptAll three vectors were validated with end-to-end integration tests against a real SSH server using the public Vulnerable ServerAny server using
Write Traversal — Write arbitrary files outside /srv/dataAn attacker crafts SCP protocol messages with
Or equivalently using standard Read Traversal — Read arbitrary files outside /srv/dataNo custom tooling needed. Standard
The server resolves
Glob Traversal — Enumerate and read files outside /srv/data
Validated Test OutputThese were confirmed with integration tests using
Tests used the real SSH handshake via ImpactAn authenticated SSH user can:
If the server uses the default authentication configuration (which accepts all connections — see RemediationFix
|
v0.3.1
initial
Dependencies (8)
|