Git-for-Windows / Git
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-62960 | Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windows | HIGH | 7.4 | Aug 21, 2026 |
| CVE-2026-32631 | Git for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary servers | HIGH | 7.4 | Apr 15, 2026 |
| CVE-2025-66413 | Git for Windows leaks NTLM hash when cloning from an attacker-controlled server | HIGH | 7.4 | Mar 10, 2026 |
| CVE-2023-29012 | Git CMD erroneously executes `doskey.exe` in the current directory, if it exists | HIGH | 7.8 | Apr 25, 2023 |
| CVE-2023-29011 | Git for Windows's config file of `connect.exe` is susceptible to malicious placing | HIGH | 7.8 | Apr 25, 2023 |
| CVE-2023-25815 | Git looks for localized messages in the wrong place | LOW | 3.3 | Apr 25, 2023 |
| CVE-2023-22743 | Git for Windows' installer is susceptible to DLL side loading attacks | HIGH | 7.3 | Feb 14, 2023 |
| CVE-2023-23618 | gitk can inadvertently call executables in the worktree | HIGH | 8.6 | Feb 14, 2023 |
| CVE-2022-41953 | Git clone remote code execution vulnerability in git-for-windows | HIGH | 8.6 | Jan 17, 2023 |
| CVE-2022-31012 | Git for Windows' installer can be tricked into executing an untrusted binary | HIGH | 8.2 | Jul 12, 2022 |
| CVE-2022-24765 | Uncontrolled search for the Git directory in Git for Windows | HIGH | 7.8 | Apr 12, 2022 |
| CVE-2021-46101 | git: git.cmd can be run directly when using git pull to update the local warehouse | HIGH | 7.5 | Jan 31, 2022 |
| CVE-2018-11235 | git: arbitrary code execution when recursively cloning a malicious repository | HIGH | 8.8 | May 30, 2018 |
Showing 1 to 13 of 13 CVEs