以下是该漏洞描述的中文翻译: 在 0.52.1 版本之前的 gitoxide 未能对 配置中的子模块名称进行有效验证,导致在推导子模块 Git 目录时存在路径遍历(Path Traversal)漏洞。攻击者可以构造带有遍历路径片段(如 )的恶意子模块名称,从而将 和 函数的目标重定向到 目录之外的仓库,进而引发仓库状态混淆,并使攻击者能够检查由其控制的仓库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitoxideLabs | gitoxide | 0 ~ 0.52.1 | - |
|
| GitoxideLabs | gitoxide | 0 ~ 0.82 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82247 | 7.5 HIGH | gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing |
| CVE-2026-82253 | 7.5 HIGH | gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass |
| CVE-2026-82254 | 7.5 HIGH | gitoxide before 0.69.0 Denial of Service via gix-pack |
| CVE-2026-82252 | 7.5 HIGH | gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules |
| CVE-2026-82255 | 6.8 MEDIUM | gitoxide 0.25.4 HTTP Credential Leak via Redirect |
| CVE-2026-82250 | 6.5 MEDIUM | gitoxide gix-packetline before 0.21.5 Denial of Service |
| CVE-2026-82248 | 5.3 MEDIUM | gitoxide before 0.33.0 Path Traversal via symlink following |
| CVE-2026-82249 | 3.1 LOW | gitoxide before 0.38.2 Credential Helper Protocol Field Injection |
No comments yet