OpenSSH ProxyCommand RCE

OpenSSH ProxyCommand RCE image
You are here:

Overview

OpenSSH has a serious bug (CVE‑2025‑61984) where an attacker can hide a newline character inside an SSH username; if your SSH config uses a ProxyCommand that inserts that username into a shell command, the hidden newline can break the command and let the attacker run whatever they put after it on your machine. In practice this can happen when someone clones a malicious Git repo with a crafted submodule URL, and shells like Bash will keep running after the broken line so the attacker’s code executes. To protect yourself, update OpenSSH to version 10.1/10.1p1 or later and, until you can patch, make ProxyCommand safer by quoting %r (for example ‘%r@%h:%p’) and avoid automatically fetching untrusted Git submodules.

Technical Details

  • Entry vector: Malicious Git repo or SSH URL with newline/control character in username.
  • Trigger: Victim runs git clone –recursive or SSH with ProxyCommand using %r.
  • Delivery: Malicious payload placed after injected newline in ProxyCommand string.
  • Execution: Shell parses multi-line command; bash/fish/csh execute attacker lines with user privileges…..

Download the Report

Date

Share

Previous Reports