CVE-2025-14946 - Libnbd: libnbd: arbitrary code execution via ssh argument injection through a ma...

CVE-2025-14946 - Libnbd: libnbd: arbitrary code execution via ssh argument injection through a ma...

CVE ID : CVE-2025-14946 Published : Dec. 19, 2025, 1:16 p.m. | 59 minutes ago Description : A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 19, 2025
Impact: code execution

Source: Telegram CVE Monitor