kas is vulnerable to Improper Certificate Validation
33
Low Risk
kas can set up SSH access for its internal git operations when triggered through environment variables. When no user SSH configuration exists, it writes a ~/.ssh/config that disables StrictHostKeyChecking, and this setting persists after kas finishes running. As a result, later SSH connections made by the same user skip host authenticity verification and become exposed to man-in-the-middle attacks. The fix limits disabling host key checking to CI environments.
You are affected if you are using a version that falls within the vulnerable range and you rely on kas internal SSH key setup via environment variables on a system without an existing ~/.ssh/config.
kas is vulnerable to Improper Certificate Validation in versions 0.0.1 - 5.3.0.
Upgrade the kas library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant