gitoxide(Rust crate gix ≤ 0.72.0 和 gix-validate ≤ 0.10.0)存在一个路径遍历漏洞。gix-validate 中的子模块名称校验函数仅通过 检查 的首次出现,使得构造的名称(例如 )能够绕过校验;此外,该校验在生产代码路径中从未被调用。结合 中的信任继承缺陷——父仓库的 ( )被克隆且跳过了所有权验证——攻击者可以构造一个恶意的 文件,使得基于 gitoxide 构建的受害工具以完全信任读取任意 git 仓库的配置(包括嵌入的凭据),从而绕过安全目录保护。该漏洞已
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GitoxideLabs | gitoxide | 0 ~ 0.82.0 | - |
|
| GitoxideLabs | gitoxide | 0 ~ 0.11.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82247 | 7.5 HIGH | gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing |
| CVE-2026-82251 | 7.5 HIGH | gitoxide before 0.52.1 Path Traversal via Submodule Name |
| CVE-2026-82254 | 7.5 HIGH | gitoxide before 0.69.0 Denial of Service via gix-pack |
| CVE-2026-82252 | 7.5 HIGH | gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules |
| CVE-2026-82255 | 6.8 MEDIUM | gitoxide 0.25.4 HTTP Credential Leak via Redirect |
| CVE-2026-82250 | 6.5 MEDIUM | gitoxide gix-packetline before 0.21.5 Denial of Service |
| CVE-2026-82248 | 5.3 MEDIUM | gitoxide before 0.33.0 Path Traversal via symlink following |
| CVE-2026-82249 | 3.1 LOW | gitoxide before 0.38.2 Credential Helper Protocol Field Injection |
No comments yet