A vulnerability labeled as critical has been found in magic-wormhole up to 0.22.x. This vulnerability affects unknown code of the file ~/.ssh/authorized_keys. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-32116. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.