Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45571

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.

A flaw was found in go-git, a Git implementation library. This path validation vulnerability allows an attacker to use specially crafted repository data. This data can cause go-git to modify or access files outside of the intended repository checkout, including critical .git directory files, potentially leading to unauthorized changes or information disclosure.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2482228github.com/go-git/go-git: go-git: Path validation flaw allows unauthorized file access

EPSS

Процентиль: 22%
0.00297
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
2 месяца назад

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.

CVSS3: 5.4
nvd
2 месяца назад

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.

CVSS3: 5.4
msrc
2 месяца назад

go-git: Crafted repositories may modify main and submodule .git directories

CVSS3: 5.4
debian
2 месяца назад

go-git is an extensible git implementation library written in pure Go. ...

CVSS3: 5.4
github
3 месяца назад

go-git: Crafted repositories may modify main and submodule .git directories

EPSS

Процентиль: 22%
0.00297
Низкий

5.4 Medium

CVSS3