CVE-2025-61985: Medium severity OpenSSH OpenSSH vulnerability
Published Oct 6, 2025
·Updated
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
Affected Software
5 affected componentsFixes available
OpenSSH OpenSSH<10.1
Microsoft cbl2 openssh 8.9p1-8
Microsoft azl3 openssh 9.8p1-4
IBM DS8A00( R10.0 - R10.1 )<=10.1.3.0 - 10.11.35.0
IBM DS8900F ( R9.4)<=89.40.83.0-89.44.25.0
Event History
Oct 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·07:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Oct 8, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:02 AM
Affected Software
Updated
via Microsoft·01:02 AM
DescriptionSeverity
Aug 19, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61985?
CVE-2025-61985 is classified as a high severity vulnerability due to the potential for code execution.
2
How do I fix CVE-2025-61985?
To fix CVE-2025-61985, upgrade OpenSSH to version 10.1 or later.
3
What does CVE-2025-61985 affect?
CVE-2025-61985 affects OpenSSH versions prior to 10.1, specifically regarding the handling of '\0' characters in ssh:// URIs.
4
Can CVE-2025-61985 lead to remote code execution?
Yes, CVE-2025-61985 can lead to remote code execution when using a ProxyCommand with vulnerable versions of OpenSSH.
5
Is CVE-2025-61985 a local or remote vulnerability?
CVE-2025-61985 is primarily considered a remote vulnerability due to exploitation through crafted ssh:// URIs.