VYPR

Gix Fs

by Gitoxide

Source repositories

CVEs (2)

  • CVE-2026-44471HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all…

  • CVE-2026-82253HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to…