VDB
BDU%3A2025-13253
BDU%3A2025-13253
PUBLISHED
CVSS 9.399999618530273 CRITICAL
Уязвимость функций checkout() и pull() расширения Git для управления версиями больших файлов Git LFS, позволяющая нарушителю получить доступ на запись произвольных файлов
Risk Scores
CVSS 2.0
9.399999618530273
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», GitHub Inc | РЕД ОС (запись в едином реестре российских программ №3751), Git LFS |
Timeline
- Oct 23, 2025 CVE Published
- Dec 8, 2025 CVE Updated
References
- https://github.com/git-lfs/git-lfs/releases/tag/v3.7.1 url
- https://github.com/git-lfs/git-lfs/commit/d02bd13f02ef76f6807581cd6b34709069cb3615 url
- https://github.com/Mitchellzhou1/CVE_2025_26625_PoC url
- https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5 advisory
- https://github.com/git-lfs/git-lfs/commit/0cffe93176b870055c9dadbb3cc9a4a440e98396 url
- https://github.com/git-lfs/git-lfs/commit/5c11ffce9a4f095ff356bc781e2a031abb46c1a8 url
- https://redos.red-soft.ru/support/secure/uyazvimosti/uyazvimost-git-lfs-cve-2025-26625/?sphrase_id=1370752 url