A Vulnerability in Git Could Allow for Remote Code Execution
ID: 99c34927-b649-58d1-82e8-319dc4443325
STIX ID: report--99c34927-b649-58d1-82e8-319dc4443325
Feed Name: CISecurity.org Advisories
This report describes CVE-2025-48384, a Git vulnerability where malicious .gitmodules entries ending with a carriage return can be used to redirect submodule contents and, in some repository layouts or when combined with symlinks, achieve arbitrary filesystem writes. An attacker who exploits this could write a malicious Git hook that triggers remote code execution when users run commands like git commit or git merge; the report does not provide evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
