CVE-2026-40034

gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-26 15:16

Updated : 2026-07-24 11:10


NVD link : CVE-2026-40034

Mitre link : CVE-2026-40034

CVE.ORG link : CVE-2026-40034


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')