GHSA-m4f9-c775-wg56HighCVSS 7.8

gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing...

Published
May 26, 2026
Last Modified
May 26, 2026

🔗 CVE IDs covered (1)

📋 Description

gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

🔗 References (7)