Количество 5
Количество 5
CVE-2026-45570
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
CVE-2026-45570
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
CVE-2026-45570
go-git: Improper single-quote escaping in go-git SSH transport
CVE-2026-45570
go-git is an extensible git implementation library written in pure Go. ...
GHSA-m7cr-m3pv-hgrp
go-git: Improper single-quote escaping in go-git SSH transport
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-45570 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4. | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-45570 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4. | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
CVE-2026-45570 go-git: Improper single-quote escaping in go-git SSH transport | 0% Низкий | 2 месяца назад | ||
CVE-2026-45570 go-git is an extensible git implementation library written in pure Go. ... | CVSS3: 9.6 | 0% Низкий | 2 месяца назад | |
GHSA-m7cr-m3pv-hgrp go-git: Improper single-quote escaping in go-git SSH transport | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу