logo

CVE-2025-48384: Git vulnerable to arbitrary file write on non-Windows systems

ID: 54a3a84e-16d5-57f3-bbd6-2497ee37f8df

STIX ID: report--54a3a84e-16d5-57f3-bbd6-2497ee37f8df

Feed Name: Datadog Security Labs

Threat Score
75/100

Date Published: 2025-07-10

Date Updated: 2026-04-27

...
...

**CVE-2025-48384 — Git arbitrary file write via `--recursive`**: Datadog Security Labs warns of a high-severity (CVSS 8.1) vulnerability in the Git CLI on macOS/Linux that can be exploited by cloning a weaponized repository with submodules (`git clone --recursive`) to achieve arbitrary file writes and potential remote code execution; public PoCs exist and affected versions prior to the patched releases (v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, v2.50.1) should be upgraded immediately, and macOS GitHub Desktop users should avoid the client until a patch is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.