Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71556

Опубликовано: 07 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.

A flaw was found in go-git, an extensible Git implementation library. Worktree operations, such as checkout, status, and add, resolve symbolic links within the working tree without proper boundary confinement. This allows a remote attacker to craft a malicious repository containing a symlink, which, when cloned and its worktree operations are used, can lead to reading from or writing to arbitrary files outside the intended working directory. This could result in information disclosure or arbitrary file modification.

Отчет

go-git is a pure-Go implementation of Git. During worktree operations (checkout, status, add), go-git resolves symbolic links without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause a consuming application to read from or write to files outside the intended working directory when that repository is cloned and its worktree operations are used. Exploitation requires the application to clone an attacker-controlled repository and then perform worktree operations against it; applications that only process trusted repositories are not exposed. Red Hat rates the impact of this flaw as Important.

Меры по смягчению последствий

To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-controller-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-image-set-controller-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/must-gather-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-must-gather-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2512562github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution

EPSS

Процентиль: 29%
0.00357
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
24 дня назад

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.

CVSS3: 7.1
nvd
24 дня назад

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.

CVSS3: 7.1
msrc
21 день назад

go-git: Worktree operations may follow symlinks

CVSS3: 7.1
debian
24 дня назад

go-git is an extensible git implementation library written in pure Go. ...

CVSS3: 7.1
github
24 дня назад

go-git: Worktree operations may follow symlinks

EPSS

Процентиль: 29%
0.00357
Низкий

7.1 High

CVSS3