Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-82252

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Aug 28, 2026
Vendor unknown

Description

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree, causing gitoxide to parse arbitrary external files as submodule configuration and expose attacker-controlled name, path, and url values.

References