CVE-2026-45571
ADVISORY - githubSummary
Impact
A path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory.
These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. Some attack vectors were platform-specific: certain payloads affected only Windows users, others affected only macOS users, and some applied across all supported platforms.
Using non-descendant go-billy filesystem instances, or different filesystem types, for the Storer and Worktree may provide some isolation against .git directory manipulation. For example, users that store the .git directory through memfs while using osfs for the worktree are not affected by this vulnerability in the main repository, because repository metadata is not materialized inside the worktree filesystem.
However, this isolation does not necessarily apply when the repository contains submodules, since submodule dotgit directories may still be represented or materialized within the worktree context.
It is important to note that exploitation requires a maliciously crafted repository payload. Users should always exercise caution when interacting with repositories or Git servers they do not trust.
Patches
Users should upgrade to a patched version in order to mitigate this vulnerability. Versions prior to v5 are likely to be affected, users are recommended to upgrade to a supported go-git version.
Credits
Thanks to @kodareef5, @AyushParkara and @N0zoM1z0 for reporting this to the go-git project in three separate reports. 🙇
Common Weakness Enumeration (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
GitHub
2.8
CVSS SCORE
5.4medium| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| github.com/go-git/go-git/v5 | golang | - | - | <=5.19.0 | 5.19.1 |
| github.com/go-git/go-git | golang | - | - | <=44.7.0 | Not yet available |
| github.com/go-git/go-git/v5 | golang | - | - | <0.0.0-20260518201055-3c3be601aa6c | 0.0.0-20260518201055-3c3be601aa6c |
| github.com/go-git/go-git/v6 | golang | - | - | <=6.0.0-alpha.3 | 6.0.0-alpha.4 |
| github.com/go-git/go-git/v6 | golang | - | - | <0.0.0-20260518135925-d9a698310823 | 0.0.0-20260518135925-d9a698310823 |
CVSS:3 Severity and metrics
The CVSS metrics represent different qualitative aspects of a vulnerability that impact the overall score, as defined by the CVSS Specification.
The vulnerable component is bound to the network stack, but the attack is limited at the protocol level to a logically adjacent topology. This can mean an attack must be launched from the same shared physical (e.g., Bluetooth or IEEE 802.11) or logical (e.g., local IP subnet) network, or from within a secure or otherwise limited administrative domain (e.g., MPLS, secure VPN to an administrative network zone). One example of an Adjacent attack would be an ARP (IPv4) or neighbor discovery (IPv6) flood leading to a denial of service on the local LAN segment (e.g., CVE-2013-6014).
Specialized access conditions or extenuating circumstances do not exist. An attacker can expect repeatable success when attacking the vulnerable component.
The attacker is unauthorized prior to attack, and therefore does not require any access to settings or files of the vulnerable system to carry out an attack.
Successful exploitation of this vulnerability requires a user to take some action before the vulnerability can be exploited. For example, a successful exploit may only be possible during the installation of an application by a system administrator.
An exploited vulnerability can only affect resources managed by the same security authority. In this case, the vulnerable component and the impacted component are either the same, or both are managed by the same security authority.
There is no loss of confidentiality.
Modification of data is possible, but the attacker does not have control over the consequence of a modification, or the amount of modification is limited. The data modification does not have a direct, serious impact on the impacted component.
Performance is reduced or there are interruptions in resource availability. Even if repeated exploitation of the vulnerability is possible, the attacker does not have the ability to completely deny service to legitimate users. The resources in the impacted component are either partially available all of the time, or fully available only some of the time, but overall there is no direct, serious consequence to the impacted component.
NIST
2.8
CVSS SCORE
5.4mediumDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumGoLang
-
Chainguard
CGA-gqmr-8jcx-g425
-
minimos
MINI-22xr-j55w-ggr3
-
minimos
MINI-23pf-mjvh-wjc3
-
minimos
MINI-2466-c92v-ff37
-
minimos
MINI-27g8-g9w6-pg3j
-
minimos
MINI-288h-wrrc-pr2x
-
minimos
MINI-2f48-2rj4-8qrc
-
minimos
MINI-2g65-whfp-7389
-
minimos
MINI-2h74-56hx-j4jg
-
minimos
MINI-2mx4-c4m4-875h
-
minimos
MINI-2qrx-xxgq-5hmj
-
minimos
MINI-2r8w-mg76-pmg5
-
minimos
MINI-2rv3-8786-4frv
-
minimos
MINI-2vr8-f97h-vr49
-
minimos
MINI-353q-9qwp-rxh8
-
minimos
MINI-384r-7p4q-mjqm
-
minimos
MINI-38v3-9qpm-g39r
-
minimos
MINI-3cc8-3gq9-p3v6
-
minimos
MINI-3j35-mgv2-rpxv
-
minimos
MINI-3jg2-xp4m-j83h
-
minimos
MINI-3jr7-r3v7-rjh9
-
minimos
MINI-3m5p-pwpc-5vwc
-
minimos
MINI-3mhw-qv5c-646j
-
minimos
MINI-3mr6-4x2q-397j
-
minimos
MINI-3rfv-6rhg-fq9p
-
minimos
MINI-4287-wmx2-qq2p
-
minimos
MINI-43jx-p52j-96w5
-
minimos
MINI-43vx-rvwg-r8fr
-
minimos
MINI-4c9p-3rx7-rwq9
-
minimos
MINI-4h55-mhhg-vfjw
-
minimos
MINI-4xmr-c6qf-hvc6
-
minimos
MINI-596m-24p3-c6pq
-
minimos
MINI-5h37-39fp-34vf
-
minimos
MINI-62hw-pgmq-j3x9
-
minimos
MINI-62mv-gmg6-rjj4
-
minimos
MINI-6666-jwx2-g5pr
-
minimos
MINI-6jm4-69hg-c54x
-
minimos
MINI-6jwh-xmw7-8h4q
-
minimos
MINI-6qgr-vprm-qr86
-
minimos
MINI-6r7h-j7ww-h45p
-
minimos
MINI-6v7f-r2jg-3q5q
-
minimos
MINI-6wmr-j2w3-7jxr
-
minimos
MINI-6x8h-mg49-q4rj
-
minimos
MINI-72gj-v9hr-w5r8
-
minimos
MINI-72ww-2vcj-gh7h
-
minimos
MINI-74cq-cwfj-h6v8
-
minimos
MINI-75jm-jj7r-33qj
-
minimos
MINI-788r-9q4v-vm7r
-
minimos
MINI-7cjc-9fcf-9xf2
-
minimos
MINI-7g34-wv75-w2mr
-
minimos
MINI-7jc5-rvrm-9c99
-
minimos
MINI-7p4v-3627-85gw
-
minimos
MINI-7x5p-2x72-wf6g
-
minimos
MINI-7x79-v7mc-4hq4
-
minimos
MINI-7x8r-x2xp-3vvf
-
minimos
MINI-8483-5524-mcrj
-
minimos
MINI-8878-wjxx-2gh9
-
minimos
MINI-88q7-6qg9-cvpr
-
minimos
MINI-8f45-97m8-8573
-
minimos
MINI-8gg7-7mj7-gp85
-
minimos
MINI-8m49-682v-v9qh
-
minimos
MINI-8p5q-4f43-2499
-
minimos
MINI-8p9v-xjrx-p84w
-
minimos
MINI-8vj3-522j-2f4w
-
minimos
MINI-923g-f98x-vf24
-
minimos
MINI-9347-v744-67h7
-
minimos
MINI-94g4-p23x-4gqw
-
minimos
MINI-97wh-58gq-9qpw
-
minimos
MINI-9j48-2hh6-hw27
-
minimos
MINI-9j4v-rvqq-98x7
-
minimos
MINI-9j8h-wqqp-p7p9
-
minimos
MINI-9rp3-hj6v-j4xf
-
minimos
MINI-9vww-8f5w-2ph6
-
minimos
MINI-c335-3f9r-9fgv
-
minimos
MINI-c4gr-r2v3-pqm3
-
minimos
MINI-c59h-6976-m6fv
-
minimos
MINI-c6v2-xq4h-qqjf
-
minimos
MINI-c895-cwjh-86vf
-
minimos
MINI-ch6f-qgvv-9pr8
-
minimos
MINI-cjmw-7m27-r4hm
-
minimos
MINI-cp77-f95v-2gvp
-
minimos
MINI-cpmf-gh3f-x9wr
-
minimos
MINI-cwmr-rvw9-7mqq
-
minimos
MINI-cx52-8rv6-wc49
-
minimos
MINI-cx6f-hr3g-x9wg
-
minimos
MINI-f6wv-395q-vpvw
-
minimos
MINI-ff47-xpj2-wqv8
-
minimos
MINI-ffcv-vp5q-84gj
-
minimos
MINI-ffrr-q7g2-6r8v
-
minimos
MINI-fph9-r82g-rj9w
-
minimos
MINI-fx7h-6pr9-2jx6
-
minimos
MINI-g267-m938-r6jq
-
minimos
MINI-g63w-mw49-mfrq
-
minimos
MINI-g89h-jx88-6fwx
-
minimos
MINI-g942-5mx9-h4qm
-
minimos
MINI-g964-89mf-qr75
-
minimos
MINI-g9cj-7x3c-gpjx
-
minimos
MINI-g9wg-fmr3-3cxw
-
minimos
MINI-gh28-9wjq-2f3v
-
minimos
MINI-gv9h-5926-8xvj
-
minimos
MINI-h2h3-743q-vxgv
-
minimos
MINI-h376-c7fg-2cq5
-
minimos
MINI-h3pm-c9m9-m3qv
-
minimos
MINI-h56g-xrcm-jvrh
-
minimos
MINI-h8gq-mwvp-qrhq
-
minimos
MINI-hgf8-g53g-rv24
-
minimos
MINI-hmwj-4pxr-46h6
-
minimos
MINI-j8qj-2pj8-c9v7
-
minimos
MINI-jfg7-7r9q-ffv4
-
minimos
MINI-jm6h-69p3-3fgx
-
minimos
MINI-jrwr-27gf-vgqw
-
minimos
MINI-jw4p-h3w4-6w6v
-
minimos
MINI-m26q-8jrp-mqr9
-
minimos
MINI-m648-pxh9-9j96
-
minimos
MINI-mc73-9h6w-vf8j
-
minimos
MINI-mfqc-pjmh-4vpx
-
minimos
MINI-mfww-cqqg-xw8c
-
minimos
MINI-mqc7-5m4x-33pg
-
minimos
MINI-mwh2-925x-h4hr
-
minimos
MINI-p25r-pq54-2q4w
-
minimos
MINI-p2p2-fqfw-m35p
-
minimos
MINI-p3wx-gp28-rmh7
-
minimos
MINI-p5v7-ccqf-7p4q
-
minimos
MINI-p624-mqcm-xc6p
-
minimos
MINI-p6q4-jw6p-xwpv
-
minimos
MINI-p967-84gm-wf28
-
minimos
MINI-p9wc-3cpp-ww3g
-
minimos
MINI-phgf-f988-9gq6
-
minimos
MINI-pv3g-hpww-gr2c
-
minimos
MINI-pwhj-ccgx-vp8g
-
minimos
MINI-q2wh-2vg2-qh94
-
minimos
MINI-q49p-fpxh-j4fq
-
minimos
MINI-q5pm-8jj3-r4h2
-
minimos
MINI-q5r7-43h7-3j2c
-
minimos
MINI-q8c9-54w7-54gv
-
minimos
MINI-r775-pp38-9c5h
-
minimos
MINI-r79w-xcx2-v89j
-
minimos
MINI-r852-34cj-54cf
-
minimos
MINI-r8rc-7g49-j4p9
-
minimos
MINI-rc3p-rc6x-mf9m
-
minimos
MINI-rchm-w77j-293h
-
minimos
MINI-rcp9-fr94-3gjq
-
minimos
MINI-rgg5-6hm3-qf7p
-
minimos
MINI-rj9w-2vf5-8x3m
-
minimos
MINI-rjrj-8gxj-2h4w
-
minimos
MINI-rqfj-4v54-x8jq
-
minimos
MINI-v2q3-cpfr-mvfg
-
minimos
MINI-v5fv-qf7r-vwp2
-
minimos
MINI-v6p5-3j9v-c27j
-
minimos
MINI-v8jm-3294-mwhc
-
minimos
MINI-v9vm-29cx-433q
-
minimos
MINI-vmr8-h46v-fxhr
-
minimos
MINI-vq6x-5p35-xfpw
-
minimos
MINI-vqx5-fp7r-jxxc
-
minimos
MINI-vx6f-6724-fr8q
-
minimos
MINI-w563-x3wg-94hq
-
minimos
MINI-w8xp-6ppx-2j4g
-
minimos
MINI-wf68-h4r8-cr5w
-
minimos
MINI-wgr6-wx5f-jvhf
-
minimos
MINI-wj74-3fm9-xhxq
-
minimos
MINI-wjj3-5f8x-4fxm
-
minimos
MINI-wqvc-c76r-7gf9
-
minimos
MINI-wr34-4568-6x8p
-
minimos
MINI-wv48-gfxv-4crj
-
minimos
MINI-wwr3-vmfw-832j
-
minimos
MINI-x2m3-x94g-9vh8
-
minimos
MINI-x6q3-pmpw-wqrf
-
minimos
MINI-x87q-jxf4-966f
-
minimos
MINI-xfmr-jr6x-h33m
-
minimos
MINI-xfwh-2h7c-p8xw
-
minimos
MINI-xg44-cgcw-3mp2
-
minimos
MINI-xghw-r3c2-8m92
-
minimos
MINI-xhcg-4jpj-wmfv
-
minimos
MINI-xmm6-m774-6wf5
-
minimos
MINI-xvc4-fj65-8w5h
-
minimos
MINI-xvvc-822p-fvp3
-