gix vulnerabilities
CVEs whose affected-version data names the gix package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-82252Highgix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
▾ Twilightgitoxide · gitoxideEPSS 0.39%via OSV
CVE-2026-82253Highgix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
▾ Twilightgix · gixEPSS 0.50%via OSV
CVE-2026-82251Highgix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
▾ Twilightgitoxide · gitoxideEPSS 0.39%via OSV
CVE-2026-40034High· 7.8gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
▾ Twilightgix · gixEPSS 0.35%via OSV