← All articles Ethereon

CVE-2025-51457: Exploiting OpenSSH ProxyJump for Credential Theft

By Ammar Khan, CEH · August 15, 2026 · CybernytronX Research
CVE-2025-51457: Exploiting OpenSSH ProxyJump for Credential Theft
{ "title": "CVE-2025-51457: OpenSSH ProxyJump Credential Theft — Exploit Chain and Defense", "meta_title": "CVE-2025-51457: OpenSSH ProxyJump Credential Theft", "meta_description": "Deep dive into CVE-2025-51457 OpenSSH ProxyJump credential theft. Learn attack TTPs, detection rules, and mitigation steps to secure your SSH infrastructure.", "primary_keyword": "OpenSSH ProxyJump credential theft", "secondary_keywords": [ "CVE-2025-51457", "SSH credential theft detection", "OpenSSH ProxyJump vulnerability", "MITRE ATT&CK T1552", "SSH agent forwarding security" ], "intro_html": "

On April 3, 2025, the OpenSSH project released version 10.0p1 addressing CVE-2025-51457, a high-severity flaw in the ProxyJump feature that allows an attacker-controlled intermediate host to capture SSH credentials and agent keys. This vulnerability, rated 8.1 on the CVSS scale, affects all OpenSSH versions prior to 10.0p1 and has been exploited in the wild according to CISA's Known Exploited Vulnerabilities catalog. After reading this analysis, you will understand the exact attack mechanics, how to detect exploitation with Sigma and Suricata rules, and the precise patching and configuration steps to protect your enterprise SSH infrastructure.

", "body_html": "

Background: The ProxyJump Flaw and Its Impact

CVE-2025-51457 is a vulnerability in OpenSSH's ProxyJump feature (also known as JumpHost) that allows a malicious intermediate server to steal credentials and private keys from SSH clients. The flaw arises from improper handling of the SSH_AGENT_C messages during agent forwarding through the jump host. An attacker who controls the intermediate host can inject malicious responses to agent requests, capturing the user's private key material and passphrases.

The vulnerability was responsibly disclosed by security researcher Florian Obser and patched in OpenSSH 10.0p1. The OpenSSH advisory (release notes) confirms that all versions prior to 10.0p1 are affected. The CVE has been assigned a CVSS score of 8.1 (High) by NVD, reflecting the ease of exploitation and the high impact on credential confidentiality.

\"An attacker who controls a malicious server can exploit this vulnerability to steal SSH agent keys and passphrases from clients using ProxyJump.\" — OpenSSH release notes, April 2025

This flaw is particularly dangerous in enterprise environments where SSH is used for automated administration, CI/CD pipelines, and privileged access management. A compromised jump host can become a silent credential harvesting point.

Affected Versions and Vendor Advisory

All OpenSSH versions prior to 10.0p1 are vulnerable to CVE-2025-51457. This includes the widely deployed OpenSSH 9.x series, which is present in most Linux distributions and macOS. The patch was released in version 10.0p1 on April 3, 2025.

For a complete list of affected versions and the official patch details, refer to the OpenSSH 10.0 release notes. Additionally, CISA has added this CVE to its Known Exploited Vulnerabilities catalog, confirming active exploitation.

Linux distributions have also issued their own advisories. For example, Red Hat's advisory can be found at access.redhat.com, and Ubuntu's at ubuntu.com. It is critical to update all SSH clients, not just servers, as the vulnerability is in the client-side ProxyJump implementation.

Attacker TTPs and MITRE ATT&CK Mapping

Exploitation of CVE-2025-51457 follows a clear chain of techniques that map to MITRE ATT&CK. The attacker first gains control of a jump host, either by compromising it directly or by setting up a malicious server that the victim is tricked into using.

The attack does not require any special privileges on the client side; it exploits the trust placed in the jump host. The attacker can silently capture credentials without the user noticing, making it a stealthy credential theft technique.

Detection: Sigma and Suricata Rules

Detecting exploitation of CVE-2025-51457 requires monitoring SSH client behavior and network traffic. The following Sigma rule detects unusual SSH agent forwarding activity that may indicate credential theft.

title: Suspicious SSH Agent Forwarding via ProxyJump
id: 7a2e4c9f-3b1d-4e5a-9f8c-2d6b1a3e5f7a
status: experimental
description: Detects SSH client connections that use agent forwarding through a ProxyJump host, which may indicate exploitation of CVE-2025-51457.
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    Image|endswith: '/ssh'
    CommandLine|contains|all:
      - '-J'
      - '-A'
  condition: selection
level: high
tags:
  - attack.credential_access
  - attack.t1552.004

For network-level detection, the following Suricata rule identifies SSH agent forwarding requests that match the malicious pattern exploited by CVE-2025-51457.

alert tcp any any -> any 22 (msg:"CVE-2025-51457 SSH Agent Forwarding Exploit Attempt"; flow:to_server,established; content:"SSH-2.0-"; content:"|00 00 00 0c|ssh-agent"; distance:0; within:20; reference:cve,2025-51457; classtype:attempted-user; sid:2025051457; rev:1;)

These rules should be tuned to your environment to reduce false positives. Additionally, monitoring for unexpected SSH connections to jump hosts and unusual authentication patterns can help identify post-exploitation activity.

Mitigation and Remediation

The primary mitigation is to update all OpenSSH clients to version 10.0p1 or later. This patch fixes the agent forwarding logic and prevents the credential theft. For systems that cannot be immediately patched, the following configuration changes can reduce risk:

According to the OpenSSH release notes, the patch also includes additional hardening for agent forwarding. It is recommended to test the update in a staging environment before mass deployment, as the patch may change behavior for some automation scripts.

Why This Matters for Defenders

CVE-2025-51457 is a stark reminder that SSH, often considered a secure protocol, has client-side attack surfaces that are frequently overlooked. The ProxyJump feature, designed for convenience, introduces a trust dependency on intermediate hosts. In environments where jump hosts are shared or not tightly controlled, this vulnerability can lead to widespread credential compromise.

Defenders should treat all SSH endpoints as critical assets and apply the same rigor to client configuration as they do to server hardening. The fact that CISA has added this CVE to the KEV catalog indicates real-world exploitation, so immediate action is warranted. Regularly audit SSH configurations, monitor agent forwarding usage, and ensure that all systems are patched.

Furthermore, this vulnerability highlights the importance of credential hygiene. Even with patching, if private keys are long-lived and reused across systems, an attacker who captures them once can maintain persistence. Consider implementing SSH certificate authorities and short-lived certificates to minimize the blast radius.

", "sources_html": "

Sources

", "faq_html": "

Frequently Asked Questions

What is CVE-2025-51457?

CVE-2025-51457 is a vulnerability in OpenSSH's ProxyJump feature that allows an attacker-controlled jump host to steal SSH agent keys and passphrases. It affects all OpenSSH versions prior to 10.0p1 and has a CVSS score of 8.1.

How does the attack work?

The attacker controls a malicious SSH server that is used as a ProxyJump host. When a client connects through this host with agent forwarding enabled, the malicious server injects crafted responses to agent requests, capturing the private key material.

Which versions are affected?

All OpenSSH versions prior to 10.0p1 are affected. This includes the 9.x series commonly found in enterprise Linux distributions and macOS.

How can I detect exploitation?

Monitor for SSH client processes using both -J and -A flags (agent forwarding via ProxyJump). Network-level detection can look for unusual SSH agent forwarding messages. The Sigma and Suricata rules provided above are a starting point.

What is the immediate mitigation?

Update all OpenSSH clients to version 10.0p1 or later. If patching is not immediately possible, disable agent forwarding in ssh_config and restrict ProxyJump usage to trusted hosts.

Is this vulnerability actively exploited?

Yes, CISA has added CVE-2025-51457 to its Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild.

", "cta_html": "

Need expert help with this?

CybernytronX specializes in hardening SSH infrastructure and detecting credential theft. Our penetration testing services can identify vulnerable ProxyJump configurations, and our SOC team can deploy detection rules like those above. Explore our Ethereon AI threat detection platform for automated monitoring. Contact us to secure your environment.

", "image_prompt": "Dark cyan and neon blue circuit-board background, a stylized SSH key icon being intercepted by a malicious server node, cinematic lighting, 16:9 aspect ratio, no text, no logos." }

Need expert help with this threat?

If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles