CVE-2025-61984 describes a vulnerability in OpenSSH versions prior to 10.1, where control characters in usernames from untrusted sources (command line or %-sequence expansion) can lead to code execution when ProxyCommand is enabled. This is a low-severity vulnerability with a CVSS score of 3.6, requiring local access and high attack complexity, primarily impacting confidentiality and integrity. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, including articles from BleepingComputer and Hacker News.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 10.1CPE match | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenSSH vulnerabilities
Mar 12, 2026OpenSSH vulnerabilities
Mar 12, 2026ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
Oct 14, 2025openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand
Oct 6, 2025