Git
Git-Scm · 41 CVEs
Git allows arbitrary code execution through broken config quoting
Jul 8, 2025
Git's protections for cloning untrusted repositories can be bypassed
May 14, 2024
Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory
May 14, 2024
Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at…
May 14, 2024
Git vulnerable to Remote Code Execution while cloning special-crafted local repositories
May 14, 2024
Arbitrary configuration injection via `git submodule deinit`
Apr 25, 2023
"git apply --reject" partially-controlled arbitrary file write
Apr 25, 2023
Git's `git apply` overwriting paths outside the working tree
Feb 14, 2023
Git vulnerable to local clone-based data exfiltration with non-local transports
Feb 14, 2023
gitattributes parsing integer overflow in git
Jan 17, 2023
Integer overflow in `git archive`, `git log --format` leading to RCE in git
Jan 17, 2023
Git clone remote code execution vulnerability in git-for-windows
Jan 17, 2023
Git vulnerable to Remote Code Execution via Heap overflow in `git shell`
Oct 19, 2022
Git subject to exposure of sensitive information via local clone of symbolic links
Oct 19, 2022
Bypass of safe.directory protections in Git
Jul 12, 2022
Uncontrolled search for the Git directory in Git for Windows
Apr 12, 2022
git: The --mirror option for git leaks secret for deleted content, aka the "GitBleed"
Feb 11, 2022
git: unexpected cross-protocol requests via a repository path containing a newline character
Aug 31, 2021
malicious repositories can execute remote code while cloning
Mar 9, 2021
Malicious URLs can still cause Git to send a stored credential to the wrong server
Apr 21, 2020
malicious URLs may cause Git to present stored credentials to the wrong server
Apr 14, 2020
git: arbitrary command execution vulnerability on case-insensitive file systems
Feb 12, 2020
git: NTFS protections inactive when running Git in the Windows Subsystem for Linux
Jan 24, 2020
git: Arbitrary path overwriting via export-marks in-stream command feature
Jan 24, 2020
git: Remote code execution in recursive clones with nested submodules
Dec 18, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-48384 KEV | Git allows arbitrary code execution through broken config quoting | HIGH | 4.20% | Jul 8, 2025 |
| CVE-2024-32465 | Git's protections for cloning untrusted repositories can be bypassed | HIGH | 1.03% | May 14, 2024 |
| CVE-2024-32021 | Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory | HIGH | 1.02% | May 14, 2024 |
| CVE-2024-32020 | Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will | LOW | 0.52% | May 14, 2024 |
| CVE-2024-32004 | Git vulnerable to Remote Code Execution while cloning special-crafted local repositories | HIGH | 1.35% | May 14, 2024 |
| CVE-2023-29007 | Arbitrary configuration injection via `git submodule deinit` | HIGH | 6.08% | Apr 25, 2023 |
| CVE-2023-25652 | "git apply --reject" partially-controlled arbitrary file write | HIGH | 51.88% | Apr 25, 2023 |
| CVE-2023-23946 | Git's `git apply` overwriting paths outside the working tree | HIGH | 1.14% | Feb 14, 2023 |
| CVE-2023-22490 | Git vulnerable to local clone-based data exfiltration with non-local transports | MEDIUM | 0.71% | Feb 14, 2023 |
| CVE-2022-23521 | gitattributes parsing integer overflow in git | CRITICAL | 56.33% | Jan 17, 2023 |
| CVE-2022-41903 | Integer overflow in `git archive`, `git log --format` leading to RCE in git | CRITICAL | 44.27% | Jan 17, 2023 |
| CVE-2022-41953 | Git clone remote code execution vulnerability in git-for-windows | HIGH | 6.80% | Jan 17, 2023 |
| CVE-2022-39260 | Git vulnerable to Remote Code Execution via Heap overflow in `git shell` | HIGH | 3.28% | Oct 19, 2022 |
| CVE-2022-39253 | Git subject to exposure of sensitive information via local clone of symbolic links | MEDIUM | 1.30% | Oct 19, 2022 |
| CVE-2022-29187 | Bypass of safe.directory protections in Git | HIGH | 0.45% | Jul 12, 2022 |
| CVE-2022-24765 | Uncontrolled search for the Git directory in Git for Windows | HIGH | 1.01% | Apr 12, 2022 |
| CVE-2022-24975 | git: The --mirror option for git leaks secret for deleted content, aka the "GitBleed" | HIGH | 2.62% | Feb 11, 2022 |
| CVE-2021-40330 | git: unexpected cross-protocol requests via a repository path containing a newline character | HIGH | 2.87% | Aug 31, 2021 |
| CVE-2021-21300 | malicious repositories can execute remote code while cloning | HIGH | 88.53% | Mar 9, 2021 |
| CVE-2020-11008 | Malicious URLs can still cause Git to send a stored credential to the wrong server | HIGH | 3.87% | Apr 21, 2020 |
| CVE-2020-5260 | malicious URLs may cause Git to present stored credentials to the wrong server | CRITICAL | 10.05% | Apr 14, 2020 |
| CVE-2014-9390 | git: arbitrary command execution vulnerability on case-insensitive file systems | CRITICAL | 75.60% | Feb 12, 2020 |
| CVE-2019-1353 | git: NTFS protections inactive when running Git in the Windows Subsystem for Linux | CRITICAL | 2.24% | Jan 24, 2020 |
| CVE-2019-1348 | git: Arbitrary path overwriting via export-marks in-stream command feature | LOW | 0.43% | Jan 24, 2020 |
| CVE-2019-1387 | git: Remote code execution in recursive clones with nested submodules | HIGH | 4.43% | Dec 18, 2019 |
Showing 1 to 25 of 41 CVEs