{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aisomorphic-gitisomorphic-gitnode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:isomorphic-git:isomorphic-git:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-89011"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["isomorphic-git (\u003c 1.42.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","prototype-pollution","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eisomorphic-git versions prior to 1.42.0 are vulnerable to a prototype pollution attack within the getRemoteInfo function. The vulnerability arises when the library parses Git ref advertisements during negotiation. By providing a specially crafted reference name containing '\u003cstrong\u003eproto\u003c/strong\u003e' segments (e.g., '\u003cstrong\u003eproto\u003c/strong\u003e/corsProxy'), a malicious Git server can inject properties into the global Object.prototype.\u003c/p\u003e\n\u003cp\u003eThis injection allows an attacker to redefine global properties used by the library. Specifically, an attacker can redirect network traffic through an arbitrary, attacker-controlled proxy server. When a client application using a vulnerable version of isomorphic-git interacts with the malicious repository, the library may trigger its onAuth callback, causing the leakage of sensitive authentication credentials to the attacker-supplied proxy. This vulnerability presents a high risk for CI/CD environments and developer tools that automate Git interactions with external, potentially untrusted repositories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the interception of authentication credentials used by applications relying on isomorphic-git. This affects any ecosystem or service performing automated Git operations on untrusted remotes, potentially leading to unauthorized access to internal development environments, private repositories, or cloud services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the isomorphic-git dependency to version 1.42.0 or later across all projects.\u003c/li\u003e\n\u003cli\u003eAudit applications for dependencies using isomorphic-git to interact with external or user-provided Git repositories.\u003c/li\u003e\n\u003cli\u003eReview CI/CD pipeline configurations to ensure that clones or fetches from untrusted repositories are executed in isolated, ephemeral environments with restricted network access.\u003c/li\u003e\n\u003cli\u003eMonitor for abnormal outbound connections originating from build servers or developer machines that execute isomorphic-git operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T23:10:11Z","date_published":"2026-09-10T23:10:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-isomorphic-git-prototype-pollution/","summary":"A prototype pollution vulnerability in isomorphic-git before 1.42.0 allows malicious Git server operators to manipulate proxy configurations and intercept credentials via crafted ref advertisements.","title":"Prototype Pollution in isomorphic-git getRemoteInfo","url":"https://feed.craftedsignal.io/briefs/2026-09-isomorphic-git-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:isomorphic-Git:isomorphic-Git:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}