Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-40034

Опубликовано: 26 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

DNE

questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

DNE

questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

needs-triage

Показывать по

EPSS

Процентиль: 28%
0.00351
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
2 месяца назад

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

CVSS3: 7.8
msrc
2 месяца назад

gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule

CVSS3: 7.8
debian
2 месяца назад

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0 ...

suse-cvrf
около 1 месяца назад

Security update for stgit

CVSS3: 7.8
github
3 месяца назад

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

EPSS

Процентиль: 28%
0.00351
Низкий

7.8 High

CVSS3