Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-40034

2 месяца назад

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-40034

2 месяца назад

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-40034

2 месяца назад

gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-40034

2 месяца назад

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0 ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21185-1

около 1 месяца назад

Security update for stgit

EPSS: Низкий
github логотип

GHSA-f26g-jm89-4g65

3 месяца назад

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-40034

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

CVSS3: 7.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-40034

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

CVSS3: 7.8
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-40034

gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule

CVSS3: 7.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-40034

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0 ...

CVSS3: 7.8
0%
Низкий
2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21185-1

Security update for stgit

0%
Низкий
около 1 месяца назад
github логотип
GHSA-f26g-jm89-4g65

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

CVSS3: 7.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу