6
CVE-2026-82248
- EPSS 0.23%
- Veröffentlicht 28.08.2026 10:49:34
- Zuletzt bearbeitet 31.08.2026 19:17:16
- Erkennungen
gitoxide before 0.33.0 Path Traversal via symlink following
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when core.symlinks is true. If a symlink entry (mode 120000) is first checked out at a path P pointing outside the worktree, a subsequent incremental checkout of a regular-file entry (mode 100644) at the same path follows the existing reparse point and writes the blob content through the link, overwriting files outside the worktree.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitoxideLabs
≫
Produkt
gitoxide
Default Statusunaffected
Version
0
Version <
0.33.0
Status
affected
Version
0.33.0
Status
unaffected
HerstellerGitoxideLabs
≫
Produkt
gitoxide
Default Statusunaffected
Version
0
Version <
0.55.0
Status
affected
Version
0.55.0
Status
unaffected
HerstellerGitoxideLabs
≫
Produkt
gitoxide
Default Statusunaffected
Version
0
Version <
0.49.0
Status
affected
Version
0.49.0
Status
unaffected
HerstellerGitoxideLabs
≫
Produkt
gitoxide
Default Statusunaffected
Version
0
Version <
0.86.0
Status
affected
Version
0.86.0
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.135 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 6 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-pmm9-4h7q-24c8
https://www.vulncheck.com/advisories/gitoxide-before-0.33.0-path-traversal-via-symlink-following