VDB
CVE-2026-82251
CVE-2026-82251
PUBLISHED
CVSS 8.7 HIGH
Reported by VulnCheck · Published August 28, 2026
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to repositories outside .git/modules, causing repository confusion and inspection of attacker-controlled repositories.
Risk Scores
CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GitoxideLabs | gitoxide | 0, 0.52.1 |
| GitoxideLabs | gitoxide | 0, 0.82.0 |
| GitoxideLabs | gitoxide | 0, 0.52.1, 0 |
| gitoxidelabs | gitoxide | 0, 0, 0 |
Timeline
- Aug 28, 2026 CVE Published
- Aug 29, 2026 EPSS Score
- Aug 29, 2026 CVE Updated
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-fr8x-3vfx-f45h) vendor-advisory
- VulnCheck Advisory: gitoxide before 0.52.1 Path Traversal via Submodule Name third-party-advisory