๐Ÿ” CVE Alert

CVE-2026-54548

LOW 3.3

kas: Persistent SSH Host Key Checking Disablement

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH_PRIVATE_KEY_FILE creates ~/.ssh/config when no user-specific SSH configuration exists and adds a global Host * rule containing StrictHostKeyChecking no. In kas/libcmds.py, ssh_no_host_key_check() runs without checking ctx.managed_env, so the setting persists after kas exits and affects future SSH sessions by the same local user, extending beyond the intended short-lived continuous integration environment. A later SSH connection can therefore accept an attacker-controlled host key without verification, increasing the risk of a man-in-the-middle attack that compromises session confidentiality or integrity. This issue is fixed in version 5.4.

CWE CWE-295
Vendor siemens
Product kas
Ecosystems
Industries
IndustrialManufacturing
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for siemens kas

Be the first to know when new low vulnerabilities affecting siemens kas are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

siemens / kas
< 5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/siemens/kas/security/advisories/GHSA-mv8m-v9v6-5f94 github.com: https://github.com/siemens/kas/commit/1c1e861c9f241ce082b86bef6bedc7da9b676294 github.com: https://github.com/siemens/kas/releases/tag/5.4