Back

HIGH

TruffleHog: specially crafted git repository can lead to arbitrary code execution

Published Oct 20, 2025

Description

An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.

Affected products

Remediation

Red Hat statement

This flaw affects only repositories copied file-for-file, such as via tar, cp, rsync or similar tools, it does not affect the regular use case of cloned repositories, limiting the impact of this vulnerability.

Red Hat mitigation

Before scanning the repository, check the contents of the .git/config file, looking for a malicious fsmonitor configuration option, such as system programs not related to project maintenance.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Oct 20, 2025
Updated Nov 3, 2025
Reserved Jul 29, 2025
CISA Vulnrichment
Updated Oct 20, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 20, 2025
ENISA EUVD
Assigner talos
Published Oct 20, 2025
Updated Nov 3, 2025
Exploited since n/a
EUVD-2025-35053