Path Validation Bypass in Gitoxide gix-fs Affects Directory Security
CVE-2026-100419

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-100419?

The gix-fs product by Gitoxide features a vulnerability that allows attackers to manipulate symlinks, resulting in a path validation bypass during the worktree checkout process. This exploitation occurs when the 'overwrite_existing' option is enabled, permitting attackers to craft malicious repository structures where symlinks replace validated directories. Consequently, files can be written outside the intended worktree, posing risks of unauthorized file manipulation or code execution. Users of gix-fs versions prior to 0.23.0 must evaluate their exposure and apply the recommended patches to mitigate this risk.

Affected Version(s)

gitoxide 0 < 0.23.0

gitoxide 0.23.0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

euriconicacio
.