Количество 6
Количество 6
CVE-2026-40034
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
CVE-2026-40034
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
CVE-2026-40034
gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
CVE-2026-40034
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0 ...
openSUSE-SU-2026:21185-1
Security update for stgit
GHSA-f26g-jm89-4g65
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-40034 gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-40034 gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-40034 gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0 ... | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21185-1 Security update for stgit | 0% Низкий | около 1 месяца назад | ||
GHSA-f26g-jm89-4g65 gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules | CVSS3: 7.8 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу