Argument Injection Vulnerability in TortoiseGit by TortoiseGit
CVE-2026-11968

5.5MEDIUM

Key Information:

Vendor
CVE Published:
24 June 2026

What is CVE-2026-11968?

An argument injection vulnerability exists in TortoiseGitBlame that can be exploited through malicious Git history filenames. This flaw enables an attacker to manipulate the input to the application, leading to arbitrary file writes. Proper sanitization and validation of filenames are essential to mitigate the risk posed by this vulnerability.

Affected Version(s)

TortoiseGit 1.8.10.0 < 2.19.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Paris of NATO Cyber Security Centre
.