PT-2026-56469 · Npm · Repomix

·

CVE-2026-59703

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions repomix (affected versions not specified)
Description A local file inclusion issue exists in the git clone endpoint. The isValidRemoteValue() function in src/core/git/gitRemoteParse.ts does not block file:// URLs. This allows unauthenticated attackers to provide file:// scheme URLs that bypass validation and are passed to the git clone process, enabling unauthorized access to the contents of tracked files within arbitrary local git repositories on the server filesystem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59703

Affected Products

Repomix