A vulnerability labeled as critical has been found in magic-wormhole up to 0.22.x. This vulnerability affects unknown code of the file ~/.ssh/authorized_keys. Such manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-32116. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.