PT-2026-83103 · Gitoxide · Gitoxide
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
gitoxide versions prior to 0.52.1
Description
Insufficient validation of submodule names within the .gitmodules configuration allows for path traversal when deriving submodule git directories. An attacker can use malicious submodule names containing traversal segments to redirect the
state() and open() functions to repositories located outside the .git/modules directory. This leads to repository confusion and allows the inspection of repositories controlled by the attacker.Recommendations
Update gitoxide to version 0.52.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitoxide