CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-28531

Critical · CVSS 9.8

OpenSSH ssh-add — Improper Access Control - smartcard keys added to ssh-agent without per-hop destination constraints

CVSS
9.8
nvd
EPSS
2.22%
81th pct
KEV
No
Class
oss containerizable
NVD-CWE-noinfo, CWE-284

Description

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

Search profile — drives PoC discovery

Symbols ssh-addssh-agentsmartcarddestination constraintsSSH_AGENT_CONSTRAIN_DESTINATIONadd_smartcard_keyssh_add_identity_constrainedSSH_AGENTC_ADD_SMARTCARD_KEY_CONSTRAINED
Keywords CVE-2023-28531OpenSSHssh-addsmartcardssh-agentdestination constraintsper-hop8.99.3improper access controlPoCproof of concept
Versions: 8.9 <= OpenSSH < 9.3

Ranked PoCs (15) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z