CVE-2025-48384High· 8.0▾ Abyssal⚠ Exploited in the wildPoC availableGit is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return a…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 44 · likelihood 0.8 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 15, 2025
Last analysed / modified upstream
4.1%
42 GitHub repos (last check)
Added to the CISA catalog on Aug 25, 2025. Federal remediation due Sep 15, 2025. View catalog ↗
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
git < 2.43.7git >= 2.44.0, < 2.44.4git >= 2.45.0, < 2.45.4git >= 2.46.0, < 2.46.4git >= 2.47.0, < 2.47.3git >= 2.48.0, < 2.48.2git >= 2.49.0, < 2.49.1git >= 2.50.0, < 2.50.1debian_linux = 11.0xcode < 26.0Upgrade past the affected range:
git 2.50.1xcode 26.0Connected by shared product, vendor, weakness, or advisory.
CVE-2015-5287High· 7.8The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…
CVE-2020-0787High· 7.8An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
CVE-2019-1069High· 7.8An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations
CVE-2021-41379Medium· 5.5Windows Installer Elevation of Privilege Vulnerability
CVE-2019-1385High· 7.8An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need …
CVE-2019-1130High· 7.8An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'