CVE-2025-48384: Git vulnerable to arbitrary file write on non-Windows systems
ID: 54a3a84e-16d5-57f3-bbd6-2497ee37f8df
STIX ID: report--54a3a84e-16d5-57f3-bbd6-2497ee37f8df
Feed Name: Datadog Security Labs
**CVE-2025-48384 — Git arbitrary file write via `--recursive`**: Datadog Security Labs warns of a high-severity (CVSS 8.1) vulnerability in the Git CLI on macOS/Linux that can be exploited by cloning a weaponized repository with submodules (`git clone --recursive`) to achieve arbitrary file writes and potential remote code execution; public PoCs exist and affected versions prior to the patched releases (v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, v2.50.1) should be upgraded immediately, and macOS GitHub Desktop users should avoid the client until a patch is released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
