Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89011

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing 'proto' path segments during ref negotiation. Attackers controlling a Git server can advertise a specially crafted ref such as 'proto/corsProxy' to reroute all subsequent network operations through an attacker-controlled proxy, causing isomorphic-git to invoke the victim's onAuth callback and transmit credentials to the attacker when the victim calls getRemoteInfo with an attacker-supplied URL.

A flaw was found in isomorphic-git. This prototype pollution vulnerability in the getRemoteInfo function allows a malicious Git server operator to manipulate object properties by advertising specially crafted reference names. This can reroute network operations through an attacker-controlled proxy, leading to the transmission of user credentials to the attacker.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backendAffected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestratorAffected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Affected
Self-service automation portal 2ansible-automation-platform/automation-portalAffected
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2531620isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function.

EPSS

Процентиль: 18%
0.00264
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
5 дней назад

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. Attackers controlling a Git server can advertise a specially crafted ref such as '__proto__/corsProxy' to reroute all subsequent network operations through an attacker-controlled proxy, causing isomorphic-git to invoke the victim's onAuth callback and transmit credentials to the attacker when the victim calls getRemoteInfo with an attacker-supplied URL.

EPSS

Процентиль: 18%
0.00264
Низкий

7.1 High

CVSS3