Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40034

Опубликовано: 26 мая 2026
Источник: debian
EPSS Низкий

Описание

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-gix-submoduleunfixedpackage
rust-gix-submoduleno-dsatrixiepackage

Примечания

  • https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f26g-jm89-4g65

  • Introduced with: https://github.com/GitoxideLabs/gitoxide/commit/6a2e6a436f76c8bbf2487f9967413a51356667a0

EPSS

Процентиль: 28%
0.00351
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

CVSS3: 7.8
nvd
2 месяца назад

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

CVSS3: 7.8
msrc
2 месяца назад

gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule

suse-cvrf
около 1 месяца назад

Security update for stgit

CVSS3: 7.8
github
3 месяца назад

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

EPSS

Процентиль: 28%
0.00351
Низкий