Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5917

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.

A flaw was found in libgit2 when built with the libssh2 SSH backend. This vulnerability allows a remote attacker to execute arbitrary commands on an SSH server. By crafting a malicious repository path containing unescaped shell metacharacters, an attacker can inject commands that are then interpreted by the remote server's shell during operations like a recursive clone. This could lead to arbitrary code execution under the victim's SSH user account.

Отчет

This is an Important flaw. Red Hat products utilizing libgit2 with the libssh2 SSH backend are susceptible to remote arbitrary code execution. This occurs when processing a maliciously crafted repository path containing unescaped shell metacharacters during a recursive clone operation, allowing an attacker to inject and execute commands on the SSH server under the victim's user account.

Меры по смягчению последствий

To mitigate this issue, avoid cloning Git repositories from untrusted sources, especially those containing submodules. If possible, disable automatic recursive cloning of submodules when working with potentially untrusted repositories. Ensure that SSH user accounts used for cloning have minimal necessary privileges to limit the impact of successful exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rustAffected
Red Hat Enterprise Linux 8libgit2Affected
Red Hat Enterprise Linux 9rustAffected
Red Hat Enterprise Linux AI (RHEL AI) 3libgit2Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rustNot affected
Red Hat Hardened Imageslibgit2Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2514416libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend

EPSS

Процентиль: 57%
0.00885
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
16 дней назад

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.

CVSS3: 9.6
nvd
16 дней назад

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.

CVSS3: 9.6
debian
16 дней назад

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH bac ...

CVSS3: 9.6
github
16 дней назад

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.

EPSS

Процентиль: 57%
0.00885
Низкий

8.8 High

CVSS3