Unrated severityOSV Advisory· Published Jan 8, 2026· Updated Jan 8, 2026
libssh key passphrase bypass without agent set
CVE-2025-15224
Description
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.