PT-2026-83101 · Gitoxide · Gitoxide
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
gitoxide versions prior to 0.38.2
Description
The software fails to validate carriage return characters in URL values passed to credential helpers. This allows attackers to supply URLs containing bare carriage returns to inject additional helper protocol fields, potentially causing credential helpers to return credentials for attacker-specified hosts instead of the requested URL.
Recommendations
Update gitoxide to version 0.38.2 or later.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitoxide