High severity7.8NVD Advisory· Published May 26, 2026· Updated Jul 24, 2026
CVE-2026-40034
CVE-2026-40034
Description
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gixcrates.io | >= 0.31.0, < 0.83.0 | 0.83.0 |
Affected products
15- Range: <0.29.0
- osv-coords12 versionspkg:apk/chainguard/cargo-auditpkg:apk/chainguard/cargo-cpkg:apk/chainguard/codexpkg:apk/chainguard/helixpkg:apk/chainguard/jujutsupkg:apk/wolfi/cargo-auditpkg:apk/wolfi/cargo-cpkg:apk/wolfi/helixpkg:rpm/opensuse/gitoxide&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/gitoxide&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/stgit&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/stgit&distro=openSUSE%20Tumbleweed
< 0.22.2-r0+ 11 more
- (no CPE)range: < 0.22.2-r0
- (no CPE)range: < 0.10.24-r0
- (no CPE)range: < 0.149.0-r0
- (no CPE)range: < 0
- (no CPE)range: < 0.41.0-r0
- (no CPE)range: < 0.22.2-r0
- (no CPE)range: < 0.10.24-r0
- (no CPE)range: < 0
- (no CPE)range: < 0.56.0-bp160.1.1
- (no CPE)range: < 0.56.0-1.1
- (no CPE)range: < 2.6.0-bp160.1.1
- (no CPE)range: < 2.6.0-1.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-f26g-jm89-4g65ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-40034ghsaADVISORY
- github.com/GitoxideLabs/gitoxide/commit/6a2e6a436f76c8bbf2487f9967413a51356667a0nvdWEB
- github.com/GitoxideLabs/gitoxide/commit/dd5c18d9e526e8de462fa40aa047acd097cfa7dcnvdWEB
- github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f26g-jm89-4g65nvdWEB
- red.anthropic.com/2026/cvd/findings/ANT-2026-6SNS6KMPnvdWEB
- www.vulncheck.com/advisories/gitoxide-command-injection-via-partial-gitmodules-override-in-gix-submodulenvdWEB
News mentions
0No linked articles in our index yet.