CVE-2026-41589 Details
Description
Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories outside the configured root directory by sending crafted filenames containing ../ sequences over the SCP protocol. This issue has been patched in version 2.0.1.
A path traversal vulnerability has been identified in the SCP middleware of Wish, an SSH server, affecting versions 2.0.0 prior to 2.0.1. The vulnerability allows a malicious SCP client to read and write arbitrary files on the server, as well as create directories outside the designated root directory. This is achieved by sending crafted filenames containing '../' sequences over the SCP protocol. The issue has been patched in version 2.0.1.
Users can update to Wish version 2.0.1, which addresses the vulnerability by fixing the path traversal issue in the SCP middleware.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/charmbracelet/wish/security/advisories/GHSA-xjvp-7243-rg9h | CISA-ADP | ExploitMitigationVendor Advisory |
| https://github.com/charmbracelet/wish/releases/tag/v2.0.1 | [email protected] | Release Notes |
| https://github.com/charmbracelet/wish/security/advisories/GHSA-xjvp-7243-rg9h | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| charm wish | 2.0.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | Initial Analysis | [email protected] |
| May 7, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | New CVE Received | [email protected] |