gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to repositories outside .git/modules, causing repository confusion and inspection of attacker-controlled repositories.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 12:16
Updated : 2026-08-29 14:16
NVD link : CVE-2026-82251
Mitre link : CVE-2026-82251
CVE.ORG link : CVE-2026-82251
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
