GHSA-449p-3h89-pw88

    Dashboard / Vulnerabilities / GHSA-449p-3h89-pw88

    GHSA-449p-3h89-pw88

    Published: 10 Jan 2024Last Modified: 10 Sept 2026

    Summary: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

    Details: ### Impact A path traversal vulnerability was discovered in go-git versions prior to `v5.11`. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. Applications are only affected if they are using the [ChrootOS](https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#ChrootOS), which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone). Applications using [BoundOS](https://pkg.go.dev/github.com/go-git/go-billy/v5/osfs#BoundOS) or in-memory filesystems are not affected by this issue. This is a `go-git` implementation issue and does not affect the upstream `git` cli. ### Patches Users running versions of `go-git` from `v4` and above are recommended to upgrade to `v5.11` in order to mitigate this vulnerability. ### Workarounds In cases where a bump to the latest version of `go-git` is not possible in a timely manner, we recommend limiting its use to only trust-worthy Git servers. ## Credit Thanks to Ionut Lalu for responsibly disclosing this vulnerability to us.

    Affected packages

    Package

    Name: github.com/go-git/go-git/v5

    Purl: pkg:golang/github.com/go-git/go-git/v5

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 5.0.0
    Fixed -5.11.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-449p-3h89-pw88 | CVE-DB