⚠ Withdrawn by GitHub Security Advisories

Withdrawn: June 30, 2026

GHSA-m4f9-c775-wg56HighCVSS 7.8Disclosed before NVD

Duplicate Advisory: gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

Published
May 26, 2026
Last Modified
June 30, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-f26g-jm89-4g65. This link is maintained to preserve external references.

Original Description

gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.

🎯 Affected products1

  • rust/gix:>= 0.31.0, < 0.83.0

🔗 References (7)