CVE-2026-5917
Reported by VulnCheck · Published August 11, 2026
libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a .gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| libgit2 | libgit2 | 0, 1.9.0 |
| libgit2 | libgit2 | 0.27.0, 0.27.0, 0.27.0 |
| alpine | libgit2 | 0, 0, 0 |
Timeline
- Aug 11, 2026 CVE Published
- Aug 12, 2026 Coalition ESS Score
- Aug 14, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-xqj4-2j5v-rr75) vendor-advisorypatch
- third-party-advisory
- Product Repository url