CVE-2026-90623 Details
Description
A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability exists in Cochise versions up to 0.4.1, specifically within the SSH Host Key Handler component. The issue arises because SSH host key verification is disabled, allowing man-in-the-middle attacks and improper validation of server certificates. This vulnerability can be exploited remotely, although it requires a high level of complexity. The exploit has been made public and could be used for attacks.
Users are advised to enable SSH host key verification, sanitize SSH output before it is ingested by the LLM, add a command validation layer between LLM output and execution, and separate standard error from standard output.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/andreashappe/cochise/ | [email protected] | Source CodeVendor |
| https://github.com/andreashappe/cochise/issues/13 | [email protected] | ExploitIssue TrackingRemedyTechnical AnalysisVendor |
| https://vuldb.com/cve/CVE-2026-90623 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/914815 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403205 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403205/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| andreashappe cochise | <= 0.4.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion