PT-2026-99131 · Unknown · Gitoxide Gix-Fs
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
gitoxide gix-fs versions prior to 0.23.0
Description
A path validation bypass exists in the worktree checkout mechanism. This issue allows attackers to escape the worktree directory through symlink manipulation. When a forced checkout is performed with
overwrite existing enabled, an attacker can create malicious repository trees where symlink entries replace validated directories. This causes subsequent files to be written outside the worktree via the symlink, potentially leading to file manipulation or code execution.Recommendations
Update gitoxide gix-fs to version 0.23.0 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitoxide Gix-Fs