Product
A symlink traversal vulnerability in the go-git library (CVE-2026-71556) enables unauthorized write access outside of the intended worktree directory when processing malicious symbolic links.