{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/libgit2-v0.27.0-through-v1.9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-5917"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libgit2 (v0.27.0 through v1.9.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["libgit2"],"content_html":"\u003cp\u003elibgit2 versions v0.27.0 through v1.9.0 are vulnerable to command injection when compiled with the libssh2 SSH backend (USE_SSH=libssh2). The flaw resides in the gen_proto() function within ssh_libssh2.c, which fails to sanitize repository path inputs before concatenating them into shell command strings. This vulnerability allows an attacker to achieve remote code execution by forcing a user or system to perform a recursive git clone of a repository containing a maliciously crafted .gitmodules file. When the client processes the submodule URL, the injected shell metacharacters - such as single quotes, semicolons, or pipes - are interpreted by the remote server's shell. This execution occurs with the privileges of the user running the git operation, posing a significant risk to CI/CD pipelines, developer workstations, and automated server environments that rely on libgit2 for repository management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to execute arbitrary shell commands under the context of the user or service account performing a git clone operation. This impacts any software, CI/CD pipeline, or automated system utilizing affected libgit2 versions, potentially leading to full system compromise, exfiltration of credentials stored in SSH agents, or lateral movement within build environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all instances of libgit2 to version 1.9.1 or later to resolve the underlying vulnerability in the gen_proto() function.\u003c/li\u003e\n\u003cli\u003eAudit build environments and CI/CD configurations to identify applications linked against the libssh2 SSH backend of libgit2.\u003c/li\u003e\n\u003cli\u003eMonitor git operations for unexpected recursive submodule processing, particularly those targeting unknown or untrusted external repositories.\u003c/li\u003e\n\u003cli\u003eImplement strict path validation and utilize SSH configurations that restrict command execution for services performing automated clones.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T01:53:30Z","date_published":"2026-08-12T01:53:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-libgit2-rce/","summary":"A command injection vulnerability in libgit2 versions v0.27.0 through v1.9.0 allows remote code execution during recursive repository clones when using the libssh2 SSH backend.","title":"Command Injection in libgit2 via libssh2 Backend","url":"https://feed.craftedsignal.io/briefs/2026-08-libgit2-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Libgit2 (V0.27.0 Through V1.9.0)","version":"https://jsonfeed.org/version/1.1"}