PT-2026-83104 · Gitoxide · Gitoxide

·

CVE-2026-82252

·

Published

2026-05-05

·

Updated

2026-08-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions gitoxide versions prior to 0.52.1
Description The software follows symlinks when reading the worktree .gitmodules file, which allows the injection of out-of-repository bytes into submodule metadata. An attacker can create a malicious repository containing a symlinked .gitmodules file that points outside the repository tree. This causes the system to parse arbitrary external files as submodule configuration, exposing attacker-controlled name, path, and url values.
Recommendations Update gitoxide to version 0.52.1 or later.

Exploit

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98415
AZL-98427
CVE-2026-82252
GHSA-PG4W-G64P-QWHJ

Affected Products

Gitoxide