CVE-2025-61984: CWE-159 Improper Handling of Invalid Use of Special Elements in OpenBSD OpenSSH
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
AI Analysis
Technical Summary
CVE-2025-61984 is a vulnerability in OpenSSH prior to version 10.1 where the ssh client allows control characters in usernames that come from untrusted sources such as the command line or %-sequence expansions in configuration files. This improper handling of special elements (CWE-159) can potentially lead to code execution when the ProxyCommand feature is used. Usernames specified as complete literals in configuration files are not considered untrusted sources and are not affected. The vulnerability has a CVSS v3.1 base score of 3.6, reflecting low severity with local attack vector, high attack complexity, low privileges required, no user interaction, and limited confidentiality and integrity impact.
Potential Impact
The vulnerability may allow an attacker with local access or the ability to influence the command line or configuration expansions to execute code via crafted usernames containing control characters when ProxyCommand is enabled. The impact is limited to confidentiality and integrity with no availability impact. The overall severity is low based on the CVSS score and required conditions.
Mitigation Recommendations
No official patch or fix information is provided in the available data. Patch status is not yet confirmed — check the OpenBSD or OpenSSH vendor advisories for current remediation guidance. Until a fix is available, avoid using untrusted sources for usernames that could contain control characters, and exercise caution when using ProxyCommand with usernames derived from command line or %-sequence expansions.
CVE-2025-61984: CWE-159 Improper Handling of Invalid Use of Special Elements in OpenBSD OpenSSH
Description
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
CVSS v3.1
Score 3.6low
Affected software
OpenBSD
OpenSSH
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-61984 is a vulnerability in OpenSSH prior to version 10.1 where the ssh client allows control characters in usernames that come from untrusted sources such as the command line or %-sequence expansions in configuration files. This improper handling of special elements (CWE-159) can potentially lead to code execution when the ProxyCommand feature is used. Usernames specified as complete literals in configuration files are not considered untrusted sources and are not affected. The vulnerability has a CVSS v3.1 base score of 3.6, reflecting low severity with local attack vector, high attack complexity, low privileges required, no user interaction, and limited confidentiality and integrity impact.
Potential Impact
The vulnerability may allow an attacker with local access or the ability to influence the command line or configuration expansions to execute code via crafted usernames containing control characters when ProxyCommand is enabled. The impact is limited to confidentiality and integrity with no availability impact. The overall severity is low based on the CVSS score and required conditions.
Mitigation Recommendations
No official patch or fix information is provided in the available data. Patch status is not yet confirmed — check the OpenBSD or OpenSSH vendor advisories for current remediation guidance. Until a fix is available, avoid using untrusted sources for usernames that could contain control characters, and exercise caution when using ProxyCommand with usernames derived from command line or %-sequence expansions.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-10-06T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68e40c3dcf87aa9c343ce4dc
Added to database: 10/06/2025, 18:36:45 UTC
Last enriched: 07/15/2026, 11:19:24 UTC
Last updated: 09/10/2026, 19:46:22 UTC
Views: 1505
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.