Path Traversal Vulnerability in Gitoxide Product by Gitoxide Labs
CVE-2026-82251

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82251?

Gitoxide versions before 0.52.1 contain a vulnerability where the software fails to properly validate submodule names specified in the .gitmodules configuration file. This oversight allows attackers to exploit the system by injecting malicious submodule names that include traversal segments. Consequently, this could lead to unauthorized redirects of the state() and open() functions to repositories located outside of the expected .git/modules directory. Such behavior can result in repository confusion and potentially let the attacker access and inspect repositories they control, compromising the integrity and confidentiality of the user's data.

Affected Version(s)

gitoxide 0 < 0.52.1

gitoxide 0 < 0.82

gitoxide 0.52.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

N0zoM1z0
.