Overview
OpenSSH has a serious bug (CVE‑2025‑61984) where an attacker can hide a newline character inside an SSH username; if your SSH config uses a ProxyCommand that inserts that username into a shell command, the hidden newline can break the command and let the attacker run whatever they put after it on your machine. In practice this can happen when someone clones a malicious Git repo with a crafted submodule URL, and shells like Bash will keep running after the broken line so the attacker’s code executes. To protect yourself, update OpenSSH to version 10.1/10.1p1 or later and, until you can patch, make ProxyCommand safer by quoting %r (for example ‘%r@%h:%p’) and avoid automatically fetching untrusted Git submodules.
Technical Details
- Entry vector: Malicious Git repo or SSH URL with newline/control character in username.
- Trigger: Victim runs git clone –recursive or SSH with ProxyCommand using %r.
- Delivery: Malicious payload placed after injected newline in ProxyCommand string.
- Execution: Shell parses multi-line command; bash/fish/csh execute attacker lines with user privileges…..



