Path Validation Bypass in Gitoxide gix-fs Affects Directory Security
CVE-2026-100419
7.3HIGH
What is CVE-2026-100419?
The gix-fs product by Gitoxide features a vulnerability that allows attackers to manipulate symlinks, resulting in a path validation bypass during the worktree checkout process. This exploitation occurs when the 'overwrite_existing' option is enabled, permitting attackers to craft malicious repository structures where symlinks replace validated directories. Consequently, files can be written outside the intended worktree, posing risks of unauthorized file manipulation or code execution. Users of gix-fs versions prior to 0.23.0 must evaluate their exposure and apply the recommended patches to mitigate this risk.
Affected Version(s)
gitoxide 0 < 0.23.0
gitoxide 0.23.0
