{"id":"CVE-2025-61985","title":"ssh in OpenSSH before 10.1 allows the '\\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.","summary":"ssh in OpenSSH before 10.1 allows the '\\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.","severity":"low","cvss":3.6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cvssSource":"cna","cwe":["CWE-158"],"vendor":"OpenBSD","product":"OpenSSH","affected":["OpenSSH < 10.1"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-10-06T18:33:49.712677Z"},"published":"2025-10-06","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:43:02.526Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-61985","references":[{"url":"https://www.openwall.com/lists/oss-security/2025/10/06/1"},{"url":"https://marc.info/?l=openssh-unix-dev&m=175974522032149&w=2"},{"url":"https://www.openssh.com/releasenotes.html#10.1p1"}],"tags":["cve.org"],"epss":0.00122,"epssPercentile":0.02311,"ingestedAt":"2026-09-08T15:33:26.996Z","slug":"CVE-2025-61985","body":"## Overview\n\nssh in OpenSSH before 10.1 allows the '\\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.\n\n## Affected\n\n- `OpenSSH < 10.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":19.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}