CVE-2026-54548

low

Description

kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH_PRIVATE_KEY_FILE creates ~/.ssh/config when no user-specific SSH configuration exists and adds a global Host * rule containing StrictHostKeyChecking no. In kas/libcmds.py, ssh_no_host_key_check() runs without checking ctx.managed_env, so the setting persists after kas exits and affects future SSH sessions by the same local user, extending beyond the intended short-lived continuous integration environment. A later SSH connection can therefore accept an attacker-controlled host key without verification, increasing the risk of a man-in-the-middle attack that compromises session confidentiality or integrity. This issue is fixed in version 5.4.

References

https://github.com/siemens/kas/security/advisories/GHSA-mv8m-v9v6-5f94

https://github.com/siemens/kas/releases/tag/5.4

https://github.com/siemens/kas/commit/1c1e861c9f241ce082b86bef6bedc7da9b676294

Details

Source: Mitre, NVD

Published: 2026-08-26

Updated: 2026-08-26

Risk Information

CVSS v2

Base Score: 2.4

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:P/A:N

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Severity: Low