6

CVE-2026-82248

gitoxide before 0.33.0 Path Traversal via symlink following

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when core.symlinks is true. If a symlink entry (mode 120000) is first checked out at a path P pointing outside the worktree, a subsequent incremental checkout of a regular-file entry (mode 100644) at the same path follows the existing reparse point and writes the blob content through the link, overwriting files outside the worktree.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitoxideLabs
≫
Produkt gitoxide
Default Statusunaffected
Version 0
Version < 0.33.0
Status affected
Version 0.33.0
Status unaffected
HerstellerGitoxideLabs
≫
Produkt gitoxide
Default Statusunaffected
Version 0
Version < 0.55.0
Status affected
Version 0.55.0
Status unaffected
HerstellerGitoxideLabs
≫
Produkt gitoxide
Default Statusunaffected
Version 0
Version < 0.49.0
Status affected
Version 0.49.0
Status unaffected
HerstellerGitoxideLabs
≫
Produkt gitoxide
Default Statusunaffected
Version 0
Version < 0.86.0
Status affected
Version 0.86.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.135
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 6 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
disclosure@vulncheck.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-pmm9-4h7q-24c8
https://www.vulncheck.com/advisories/gitoxide-before-0.33.0-path-traversal-via-symlink-following