Логотип exploitDog
bind:CVE-2025-26625
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-26625

Количество 12

Количество 12

ubuntu логотип

CVE-2025-26625

3 месяца назад

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these commands. As well, when the git lfs checkout and git lfs pull commands are run in a bare repository, they could write to files visible outside the repository. The vulnerability is fixed in version 3.7.1. As a workaround, support for symlinks in Git may be disabled by setting the core.symlinks configuration option to false, after whic...

EPSS: Низкий
nvd логотип

CVE-2025-26625

3 месяца назад

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these commands. As well, when the git lfs checkout and git lfs pull commands are run in a bare repository, they could write to files visible outside the repository. The vulnerability is fixed in version 3.7.1. As a workaround, support for symlinks in Git may be disabled by setting the core.symlinks configuration option to false, after which f

EPSS: Низкий
debian логотип

CVE-2025-26625

3 месяца назад

Git LFS is a Git extension for versioning large files. In Git LFS vers ...

EPSS: Низкий
rocky логотип

RLSA-2025:23745

24 дня назад

Important: git-lfs security update

EPSS: Низкий
rocky логотип

RLSA-2025:23744

24 дня назад

Important: git-lfs security update

EPSS: Низкий
rocky логотип

RLSA-2025:23667

27 дней назад

Important: git-lfs security update

EPSS: Низкий
github логотип

GHSA-6pvw-g552-53c5

3 месяца назад

Git LFS may write to arbitrary files via crafted symlinks

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23745

27 дней назад

ELSA-2025-23745: git-lfs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23744

27 дней назад

ELSA-2025-23744: git-lfs security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23667

30 дней назад

ELSA-2025-23667: git-lfs security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-13253

3 месяца назад

Уязвимость функций checkout() и pull() расширения Git для управления версиями больших файлов Git LFS, позволяющая нарушителю получить доступ на запись произвольных файлов

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20251203-13

около 1 месяца назад

Уязвимость git-lfs

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-26625

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these commands. As well, when the git lfs checkout and git lfs pull commands are run in a bare repository, they could write to files visible outside the repository. The vulnerability is fixed in version 3.7.1. As a workaround, support for symlinks in Git may be disabled by setting the core.symlinks configuration option to false, after whic...

0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-26625

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these commands. As well, when the git lfs checkout and git lfs pull commands are run in a bare repository, they could write to files visible outside the repository. The vulnerability is fixed in version 3.7.1. As a workaround, support for symlinks in Git may be disabled by setting the core.symlinks configuration option to false, after which f

0%
Низкий
3 месяца назад
debian логотип
CVE-2025-26625

Git LFS is a Git extension for versioning large files. In Git LFS vers ...

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:23745

Important: git-lfs security update

0%
Низкий
24 дня назад
rocky логотип
RLSA-2025:23744

Important: git-lfs security update

0%
Низкий
24 дня назад
rocky логотип
RLSA-2025:23667

Important: git-lfs security update

0%
Низкий
27 дней назад
github логотип
GHSA-6pvw-g552-53c5

Git LFS may write to arbitrary files via crafted symlinks

0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2025-23745

ELSA-2025-23745: git-lfs security update (IMPORTANT)

27 дней назад
oracle-oval логотип
ELSA-2025-23744

ELSA-2025-23744: git-lfs security update (IMPORTANT)

27 дней назад
oracle-oval логотип
ELSA-2025-23667

ELSA-2025-23667: git-lfs security update (IMPORTANT)

30 дней назад
fstec логотип
BDU:2025-13253

Уязвимость функций checkout() и pull() расширения Git для управления версиями больших файлов Git LFS, позволяющая нарушителю получить доступ на запись произвольных файлов

CVSS3: 8.1
0%
Низкий
3 месяца назад
redos логотип
ROS-20251203-13

Уязвимость git-lfs

CVSS3: 8.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу