Information Disclosure in GitHub Desktop by GitHub
CVE-2025-48064
What is CVE-2025-48064?
GitHub Desktop, an open-source application designed for Git development, is vulnerable to information disclosure prior to version 3.4.20-beta3. This vulnerability arises when a user is manipulated into viewing a malicious commit in the application's history view. In such cases, the software may attempt to access network shares because of how it processes file diffs. Specifically, Git tries to resolve the paths of old and new file names, which could inadvertently trigger attempts to authenticate through NTLM on Windows, exposing sensitive information like usernames and NTLM hashes. Users of GitHub Desktop are strongly advised to upgrade to version 3.4.20 or later to mitigate this risk. Until an upgrade, it is recommended to only view commits from trusted sources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
desktop < 3.4.20-beta3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
