CVE-2026-82252
gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree, causing gitoxide to parse arbitrary external files as submodule configuration and expose attacker-controlled name, path, and url values.
| CWE | CWE-59 |
| Vendor | gitoxidelabs |
| Product | gitoxide |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for gitoxidelabs gitoxide
Be the first to know when new high vulnerabilities affecting gitoxidelabs gitoxide are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
GitoxideLabs / gitoxide
0 < 0.52.1
GitoxideLabs / gitoxide
0 < 0.82
References
Credits
๐ N0zoM1z0