{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gitoxide--0.52.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82252"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gitoxide (\u003c 0.52.1)","gitoxide"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Gitoxide"],"content_html":"\u003cp\u003eGitoxide, a pure Rust implementation of Git, is vulnerable to a path traversal issue (CVE-2026-82252) affecting versions before 0.52.1. The flaw resides in how the tool processes the '.gitmodules' file within a worktree. When parsing this file, gitoxide fails to validate that the file location remains within the confines of the repository, allowing it to follow symbolic links. An attacker can create a malicious repository containing a '.gitmodules' file that is actually a symlink to sensitive files elsewhere on the host system. When a victim uses an affected version of gitoxide to interact with this repository, the tool parses the target file, potentially exposing sensitive data or injecting attacker-controlled values into the submodule metadata (path, name, and URL). This could lead to further exploitation, such as the execution of malicious code during subsequent submodule update operations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to influence the configuration of Git submodules by injecting contents from arbitrary files on the victim's filesystem. This behavior could be leveraged to redirect submodule fetches to malicious servers or facilitate command execution depending on how the parsed metadata is consumed by the victim's environment. The vulnerability impacts any developer or automated build system utilizing versions of gitoxide below 0.52.1 to process untrusted repositories.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the gitoxide library to version 0.52.1 or higher across all development environments, CI/CD pipelines, and server-side infrastructure.\u003c/li\u003e\n\u003cli\u003eAudit repositories processed by affected versions of gitoxide for unexpected symbolic links within the worktree, specifically targeting the '.gitmodules' file.\u003c/li\u003e\n\u003cli\u003eDeploy environment-level restrictions to prevent user-space tools from traversing outside of known project directories if the environment regularly interacts with untrusted git repositories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T15:13:28Z","date_published":"2026-08-28T13:14:53Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gitoxide-symlink-vulnerability/","summary":"Gitoxide versions prior to 0.52.1 contain a path traversal vulnerability via symlink following that allows attackers to inject arbitrary file contents into submodule configuration metadata.","title":"Path Traversal Vulnerability in gitoxide","url":"https://feed.craftedsignal.io/briefs/2026-08-gitoxide-symlink-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Gitoxide (\u003c 0.52.1)","version":"https://jsonfeed.org/version/1.1"}