logo

A Vulnerability in Git Could Allow for Remote Code Execution

ID: 99c34927-b649-58d1-82e8-319dc4443325

STIX ID: report--99c34927-b649-58d1-82e8-319dc4443325

Feed Name: CISecurity.org Advisories

Threat Score
80/100

Date Published: 2025-08-27

Date Updated: 2026-04-27

...
...

This report describes CVE-2025-48384, a Git vulnerability where malicious .gitmodules entries ending with a carriage return can be used to redirect submodule contents and, in some repository layouts or when combined with symlinks, achieve arbitrary filesystem writes. An attacker who exploits this could write a malicious Git hook that triggers remote code execution when users run commands like git commit or git merge; the report does not provide evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.