CVE-2026-59703High· 7.5▾ MidnightPoC availablerepomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to bl…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.5%
repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to block file:// URLs, permitting attackers to supply file:// scheme URLs that bypass validation and are passed directly to git clone, enabling unauthorized access to all tracked file contents on the server filesystem.
repomix < 1.14.1repomix <= c748b52Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59702Critical· 9.3repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack
CVE-2026-49987High· 8.8repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
CVE-2026-49988Mediumrepomix: attach_packed_output can bypass file-read secret scanning for supported local files
CVE-2026-88623High· 7.5NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read
CVE-2026-77884High· 7.1Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network
CVE-2021-1256Medium· 6.0A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques