Git / Git
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-48384 KEV | Git allows arbitrary code execution through broken config quoting | HIGH | 8.1 | Jul 8, 2025 |
| CVE-2025-48385 | Git alllows arbitrary file writes via bundle-uri parameter injection | HIGH | 8.6 | Jul 8, 2025 |
| CVE-2025-48386 | Git allows a buffer overflow in 'wincred' credential helper | MEDIUM | 6.3 | Jul 8, 2025 |
| CVE-2024-52005 | The sideband payload is passed unfiltered to the terminal in git | HIGH | 7.5 | Jan 15, 2025 |
| CVE-2024-50349 | Git does not sanitize URLs when asking for credentials interactively | LOW | 2.1 | Jan 14, 2025 |
| CVE-2024-52006 | Newline confusion in credential helpers can lead to credential exfiltration in git | LOW | 2.1 | Jan 14, 2025 |
| CVE-2024-32465 | Git's protections for cloning untrusted repositories can be bypassed | HIGH | 7.8 | May 14, 2024 |
| CVE-2024-32021 | Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory | HIGH | 7.1 | May 14, 2024 |
| CVE-2024-32020 | Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will | LOW | 3.9 | May 14, 2024 |
| CVE-2024-32004 | Git vulnerable to Remote Code Execution while cloning special-crafted local repositories | HIGH | 8.2 | May 14, 2024 |
| CVE-2024-32002 | Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution | CRITICAL | 9.1 | May 14, 2024 |
| CVE-2023-29007 | Arbitrary configuration injection via `git submodule deinit` | HIGH | 7.8 | Apr 25, 2023 |
| CVE-2023-25652 | "git apply --reject" partially-controlled arbitrary file write | HIGH | 7.5 | Apr 25, 2023 |
| CVE-2023-23946 | Git's `git apply` overwriting paths outside the working tree | HIGH | 7.5 | Feb 14, 2023 |
| CVE-2023-22490 | Git vulnerable to local clone-based data exfiltration with non-local transports | MEDIUM | 5.5 | Feb 14, 2023 |
| CVE-2022-23521 | gitattributes parsing integer overflow in git | CRITICAL | 9.8 | Jan 17, 2023 |
| CVE-2022-41903 | Integer overflow in `git archive`, `git log --format` leading to RCE in git | CRITICAL | 9.8 | Jan 17, 2023 |
| CVE-2022-39260 | Git vulnerable to Remote Code Execution via Heap overflow in `git shell` | HIGH | 8.8 | Oct 19, 2022 |
| CVE-2022-39253 | Git subject to exposure of sensitive information via local clone of symbolic links | MEDIUM | 5.5 | Oct 19, 2022 |
| CVE-2022-29187 | Bypass of safe.directory protections in Git | HIGH | 7.8 | Jul 12, 2022 |
| CVE-2022-25648 | Command Injection | CRITICAL | 9.8 | Apr 19, 2022 |
| CVE-2021-23632 | Remote Code Execution (RCE) | CRITICAL | 9.8 | Mar 17, 2022 |
| CVE-2021-21300 | malicious repositories can execute remote code while cloning | HIGH | 8.0 | Mar 9, 2021 |
| CVE-2020-11008 | Malicious URLs can still cause Git to send a stored credential to the wrong server | HIGH | 7.5 | Apr 21, 2020 |
| CVE-2020-5260 | malicious URLs may cause Git to present stored credentials to the wrong server | CRITICAL | 9.3 | Apr 14, 2020 |
Showing 1 to 25 of 35 CVEs