CVE-2023-51385
MEDIUM 6.5EPSS 19.8%
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 19.75% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2023-12-18
- Updated
- 2026-07-14
Proof-of-concept exploits (24)
- 2048JiaLi/CVE-2023-513850★ · 2024-01-30
- FeatherStark/CVE-2023-513850★ · 2023-12-25
- Featherw1t/CVE-2023-51385_test0★ · 2024-08-20
- GroundCTL2MajorTom/CVE-2023-51385P-POC0★ · 2025-01-06
- GroundCTL2MajorTom/CVE-2023-51385POC0★ · 2025-01-06
- Le1a/CVE-2023-513855★ · 2023-12-26
- LtmThink/CVE-2023-51385_test7★ · 2024-03-17
- MiningBot-eth/CVE-2023-51385-exploit0★ · 2024-06-15
- Sonicrrrr/CVE-2023-513850★ · 2024-01-09
- WLaoDuo/CVE-2023-51385_poc-test0★ · 2023-12-27
- WOOOOONG/CVE-2023-513852★ · 2024-01-02
- c0deur/CVE-2023-513850★ · 2024-05-27
- endasugrue/CVE-2023-51385_poc0★ · 2024-06-12
- farliy-hacker/CVE-2023-513850★ · 2024-01-20
- farliy-hacker/CVE-2023-51385-save0★ · 2024-01-20
- julienbrs/exploit-CVE-2023-513850★ · 2024-01-03
- julienbrs/malicious-exploit-CVE-2023-513850★ · 2024-01-03
- power1314520/CVE-2023-51385_test0★ · 2023-12-30
- saarcastified/CVE-2023-51385---OpenSSH-ProxyCommand-Injection-PoC0★ · 2025-07-29
- thinkliving2020/CVE-2023-51385-0★ · 2024-04-16
- vin01/poc-proxycommand-vulnerable50★ · 2023-10-12
- watarium/poc-cve-2023-513850★ · 2023-12-27
- zls1793/CVE-2023-51385_test7★ · 2024-03-17
- kr-ale/Stapler