VYPR
Medium severity6.5NVD Advisory· Published Dec 18, 2023· Updated May 12, 2026

CVE-2023-51385

CVE-2023-51385

Description

In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.

Affected products

1
  • OpenSSH/OpenSSHdescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.