VDB
GO-2025-3390
GO-2025-3390
PUBLISHED
Git LFS permits exfiltration of credentials via crafted HTTP URLs in github.com/git-lfs/git-lfs
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | git-lfs/git-lfs/v3 | 3.0.0, 3.0.0 |
| github.com | git-lfs/git-lfs | 0.1.0, 0.1.0 |
Timeline
- Jan 15, 2025 CVE Published
- Mar 3, 2026 CVE Updated