Symlink Injection Vulnerability in Gitoxide by Gitoxide Labs
CVE-2026-82252

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82252?

The vulnerability in Gitoxide allows for the exploitation of symlink handling in .gitmodules files. By creating a malicious repository with a symlinked .gitmodules file that points outside the repository tree, attackers can manipulate the reading process, causing Gitoxide to parse external files as if they were legitimate submodule configurations. This could lead to exposure of attacker-controlled values for name, path, and URL, significantly compromising the integrity of the repository.

Affected Version(s)

gitoxide 0 < 0.52.1

gitoxide 0 < 0.82

gitoxide 0.52.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

N0zoM1z0
.