PT-2026-83104 · Gitoxide · Gitoxide
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
gitoxide versions prior to 0.52.1
Description
The software follows symlinks when reading the worktree
.gitmodules file, which allows the injection of out-of-repository bytes into submodule metadata. An attacker can create a malicious repository containing a symlinked .gitmodules file that points outside the repository tree. This causes the system to parse arbitrary external files as submodule configuration, exposing attacker-controlled name, path, and url values.Recommendations
Update gitoxide to version 0.52.1 or later.
Exploit
Fix
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitoxide