VYPR
Low severity3.6NVD Advisory· Published Oct 6, 2025· Updated Apr 15, 2026

CVE-2025-61984

CVE-2025-61984

Description

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

62

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.