{"schema_version":"1.9.0","id":"CVE-2025-5689","published":"2025-06-16T11:37:12.230Z","modified":"2026-08-27T03:57:06.719490689Z","aliases":["GHSA-g8qw-mgjx-rwjr","GO-2025-3762"],"related":["openSUSE-SU-2025:15405-1"],"summary":"Improper Permission Management in SSH Session Handling","details":"A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/authd","events":[{"introduced":"0"},{"fixed":"f97279aeb2887ef885d099c3c6b2487fc8f24ab4"}],"database_specific":{"cpe":"cpe:2.3:a:canonical:authd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.0.0"},{"last_affected":"0.5.4"},{"introduced":"0"},{"fixed":"0.5.4"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v0.3.7","v0.3.6","v0.3.5","0.3.5","v0.3.3","v0.3.2","v0.2.1","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5689.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5689.json"},{"type":"ADVISORY","url":"https://github.com/ubuntu/authd/security/advisories/GHSA-g8qw-mgjx-rwjr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5689"}],"database_specific":{"cna_assigner":"canonical","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5689.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"}]}