{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gix--0.72.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82253"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gix (\u003c= 0.72.0)","gix-validate (\u003c= 0.10.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","supply-chain","gitoxide","rust"],"_cs_type":"advisory","_cs_vendors":["gitoxide"],"content_html":"\u003cp\u003eThe gitoxide project (gix and gix-validate crates) contains a path traversal vulnerability that, when combined with an insecure trust inheritance flaw in Submodule::open(), allows an attacker to compromise repositories using these libraries. The validation function in gix-validate only checks for the first occurrence of '..' in submodule names, which can be bypassed using crafted strings such as 'a..b/../../../.git/'. Furthermore, this validation is not invoked in active code paths. The vulnerability is amplified by a trust inheritance flaw in Submodule::open(), where parent repository trust levels (Trust::Full) are incorrectly propagated to submodules, bypassing ownership verification and safe-directory protections. An attacker can craft a malicious .gitmodules file to force applications using gitoxide to read arbitrary repository configurations, potentially exposing embedded credentials or executing actions with unintended privileges. The vulnerability was addressed in gix version 0.82.0 and gix-validate version 0.11.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the reading of sensitive git repository configurations, including embedded credentials, potentially impacting any software built on the affected versions of the gitoxide ecosystem. It bypasses established safe-directory security mechanisms, increasing the risk of unauthorized repository access or data exfiltration in development environments or CI/CD pipelines.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all projects using the gitoxide library to the patched versions immediately. Developers should audit usage of Submodule::open() and ensure that inputs from external .gitmodules files are sanitized before processing.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the gix crate to version 0.82.0 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade the gix-validate crate to version 0.11.1 or later.\u003c/li\u003e\n\u003cli\u003eAudit repositories for unusually formatted entries in .gitmodules files, specifically those containing directory traversal sequences.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T15:13:34Z","date_published":"2026-08-28T15:13:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gitoxide-path-traversal/","summary":"A path traversal and trust inheritance vulnerability in the gitoxide Rust crates allows attackers to access arbitrary git configurations by crafting malicious .gitmodules files.","title":"Path Traversal and Trust Inheritance Vulnerability in gitoxide","url":"https://feed.craftedsignal.io/briefs/2026-08-gitoxide-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Gix (\u003c= 0.72.0)","version":"https://jsonfeed.org/version/1.1"}