{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agitoxidegix-fs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gitoxide:gix-fs:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-100419"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gix-fs (\u003c 0.23.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","library-vulnerability"],"_cs_type":"advisory","_cs_vendors":["gitoxide"],"content_html":"\u003cp\u003eThe gitoxide gix-fs library, specifically versions prior to 0.23.0, contains a critical path validation bypass vulnerability within its worktree checkout mechanism. This vulnerability arises when the library performs a forced checkout with the 'overwrite_existing' configuration enabled. An attacker can create a specially crafted repository tree containing symlink entries designed to replace previously validated directories. During the checkout process, the library fails to adequately validate the target path of these symlinks, allowing the system to follow them and write subsequent files into arbitrary locations outside the designated worktree directory. This flaw presents a significant security risk, as it enables local file manipulation or potential code execution if an attacker can force a victim to clone or checkout a malicious repository using an affected version of the library.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-100419 allows an attacker to overwrite arbitrary files on the host filesystem that the process running the gitoxide-based application has permission to modify. This can result in unauthorized file system access, modification of configuration files, or the planting of malicious scripts for subsequent execution. This affects any software or developer tool integrated with the gix-fs library prior to version 0.23.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all applications utilizing the gitoxide gix-fs crate to version 0.23.0 or later to remediate CVE-2026-100419.\u003c/li\u003e\n\u003cli\u003eAudit build environments and CI/CD pipelines that pull and process untrusted Git repositories for the use of vulnerable library versions.\u003c/li\u003e\n\u003cli\u003eImplement filesystem sandboxing or restrict process privileges for tools that execute git checkout operations on untrusted content.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T22:55:58Z","date_published":"2026-09-25T22:55:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gitoxide-path-bypass/","summary":"The gitoxide gix-fs library before version 0.23.0 is vulnerable to a path validation bypass during worktree checkout that allows arbitrary file writes outside the intended directory via symlink manipulation.","title":"Path Validation Bypass in gitoxide gix-fs","url":"https://feed.craftedsignal.io/briefs/2026-09-gitoxide-path-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gitoxide:gix-Fs:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}