gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-26 15:16
Updated : 2026-07-24 11:10
NVD link : CVE-2026-40034
Mitre link : CVE-2026-40034
CVE.ORG link : CVE-2026-40034
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
