3.1
CVE-2025-15224
- EPSS 0.42%
- Veröffentlicht 08.01.2026 10:15:47
- Zuletzt bearbeitet 20.01.2026 14:47:52
- CVE-Watchlists
- Unerledigt
libssh key passphrase bypass without agent set
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.346 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://curl.se/docs/CVE-2025-15224.html
https://curl.se/docs/CVE-2025-15224.json
https://hackerone.com/reports/3480925
http://www.openwall.com/lists/oss-security/2026/01/07/7