CVE-2026-41589Disclosure(charm / wish)

LOWCVSS 9.6 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories outside the configured root directory by sending crafted filenames containing ../ sequences over the SCP protocol. This issue has been patched in version 2.0.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wish

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
wish

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-13: 3Technical Details · 2026-05-13: 105-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-41589 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory Wish is an SSH server with defaults and a collection of middlewares.

    Post summary

    The post announces a critical CVE-2026-41589 for the Wish SSH server, providing CVSS and severity information but offering no additional technical details, mitigation advice, or evidence of active exploitation.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.6 CRITICAL · CVE-2026-41589 · 9.6 → 2.0.0 CVE: CVE-2026-41589 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The message announces CVE‑2026‑41589 as a critical vulnerability with a CVSS 9.6 rating, providing only its severity and vector details, but no evidence of exploitation or mitigations.

    1000041
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-41589-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    A link to a CVE-2026-41589 advisory is shared on social media, but the post lacks any concrete details about the vulnerability, PoC, exploit, or mitigation.

    0000020
    210 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcharmwish2.0.0--

Explore more