JLSEC-2025-7

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2025/JLSEC-2025-7.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-7.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2025-7
Aliases
  • CVE-2025-61984
Published
2025-10-09T17:08:38.385Z
Modified
2025-11-25T22:31:31.909148Z
Summary
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possib...
Details

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "imported": "2025-11-12T03:31:42.329Z",
            "id": "CVE-2025-61984",
            "published": "2025-10-06T19:15:36.157Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-61984",
            "modified": "2025-11-11T15:15:36.703Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61984"
        },
        {
            "imported": "2025-11-12T03:31:42.518Z",
            "id": "EUVD-2025-32089",
            "published": "2025-10-06T21:30:45Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-32089",
            "fields": [
                "affected"
            ],
            "modified": "2025-11-11T15:31:19Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-32089"
        }
    ]
}
References

Affected packages

Julia / OpenSSH_jll

Package

Name
OpenSSH_jll
Purl
pkg:julia/OpenSSH_jll?uuid=9bd350c2-7e96-507f-8002-3f2e150b4e1b

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.1.1+0

Database specific

source

"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2025/JLSEC-2025-7.json"