CPE
The gitoxide gix-fs library before version 0.23.0 is vulnerable to a path validation bypass during worktree checkout that allows arbitrary file writes outside the intended directory via symlink manipulation.