Git

Git-Scm · 41 CVEs

CVE-2025-48384
KEV HIGH

Git allows arbitrary code execution through broken config quoting

Jul 8, 2025

CVE-2024-32465
HIGH

Git's protections for cloning untrusted repositories can be bypassed

May 14, 2024

CVE-2024-32021
HIGH

Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory

May 14, 2024

CVE-2024-32020
LOW

Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at…

May 14, 2024

CVE-2024-32004
HIGH

Git vulnerable to Remote Code Execution while cloning special-crafted local repositories

May 14, 2024

CVE-2023-29007
HIGH

Arbitrary configuration injection via `git submodule deinit`

Apr 25, 2023

CVE-2023-25652
HIGH

"git apply --reject" partially-controlled arbitrary file write

Apr 25, 2023

CVE-2023-23946
HIGH

Git's `git apply` overwriting paths outside the working tree

Feb 14, 2023

CVE-2023-22490
MEDIUM

Git vulnerable to local clone-based data exfiltration with non-local transports

Feb 14, 2023

CVE-2022-23521
CRITICAL

gitattributes parsing integer overflow in git

Jan 17, 2023

CVE-2022-41903
CRITICAL

Integer overflow in `git archive`, `git log --format` leading to RCE in git

Jan 17, 2023

CVE-2022-41953
HIGH

Git clone remote code execution vulnerability in git-for-windows

Jan 17, 2023

CVE-2022-39260
HIGH

Git vulnerable to Remote Code Execution via Heap overflow in `git shell`

Oct 19, 2022

CVE-2022-39253
MEDIUM

Git subject to exposure of sensitive information via local clone of symbolic links

Oct 19, 2022

CVE-2022-29187
HIGH

Bypass of safe.directory protections in Git

Jul 12, 2022

CVE-2022-24765
HIGH

Uncontrolled search for the Git directory in Git for Windows

Apr 12, 2022

CVE-2022-24975
HIGH

git: The --mirror option for git leaks secret for deleted content, aka the "GitBleed"

Feb 11, 2022

CVE-2021-40330
HIGH

git: unexpected cross-protocol requests via a repository path containing a newline character

Aug 31, 2021

CVE-2021-21300
HIGH

malicious repositories can execute remote code while cloning

Mar 9, 2021

CVE-2020-11008
HIGH

Malicious URLs can still cause Git to send a stored credential to the wrong server

Apr 21, 2020

CVE-2020-5260
CRITICAL

malicious URLs may cause Git to present stored credentials to the wrong server

Apr 14, 2020

CVE-2014-9390
CRITICAL

git: arbitrary command execution vulnerability on case-insensitive file systems

Feb 12, 2020

CVE-2019-1353
CRITICAL

git: NTFS protections inactive when running Git in the Windows Subsystem for Linux

Jan 24, 2020

CVE-2019-1348
LOW

git: Arbitrary path overwriting via export-marks in-stream command feature

Jan 24, 2020

CVE-2019-1387
HIGH

git: Remote code execution in recursive clones with nested submodules

Dec 18, 2019

Showing 1 to 25 of 41 CVEs