{"api_version":"1","generated_at":"2026-10-03T02:21:16+00:00","cve":"CVE-2025-48384","urls":{"html":"https://cve.report/CVE-2025-48384","api":"https://cve.report/api/cve/CVE-2025-48384.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-48384","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-48384"},"summary":{"title":"Git allows arbitrary code execution through broken config quoting","description":"Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2025-07-08 19:15:42","updated_at":"2026-09-24 13:10:00"},"problem_types":["CWE-59","CWE-436","CWE-436 CWE-436: Interpretation Conflict","CWE-59 CWE-59: Improper Link Resolution Before File Access ('Link Following')"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2025/07/08/4","name":"http://www.openwall.com/lists/oss-security/2025/07/08/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48384","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48384","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9","name":"https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9","refsource":"security-advisories@github.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00003.html","name":"https://lists.debian.org/debian-lts-announce/2025/10/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://seclists.org/fulldisclosure/2025/Sep/60","name":"http://seclists.org/fulldisclosure/2025/Sep/60","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-48384","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48384","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"git","product":"git","version":"affected < 2.43.7","platforms":[]},{"source":"CNA","vendor":"git","product":"git","version":"affected >= 2.44.0-rc0, < 2.44.4","platforms":[]},{"source":"CNA","vendor":"git","product":"git","version":"affected >= 2.45.0-rc0, < 2.45.4","platforms":[]},{"source":"CNA","vendor":"git","product":"git","version":"affected >= 2.46.0-rc0, < 2.46.4","platforms":[]},{"source":"CNA","vendor":"git","product":"git","version":"affected >= 2.47.0-rc0, < 2.47.3","platforms":[]},{"source":"CNA","vendor":"git","product":"git","version":"affected >= 2.48.0-rc0, < 2.48.2","platforms":[]},{"source":"CNA","vendor":"git","product":"git","version":"affected >= 2.49.0-rc0, < 2.49.1","platforms":[]},{"source":"CNA","vendor":"git","product":"git","version":"affected >= 2.50.0-rc0, < 2.50.1","platforms":[]}],"timeline":[{"source":"ADP","time":"2025-08-25T00:00:00.000Z","lang":"en","value":"CVE-2025-48384 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"48384","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"git-scm","cpe5":"git","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2025","cve_id":"48384","cve":"CVE-2025-48384","vendorProject":"Git","product":"Git","vulnerabilityName":"Git Link Following Vulnerability","dateAdded":"2025-08-25","shortDescription":"Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-09-15","knownRansomwareCampaignUse":"Unknown","notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9 ; https://access.redhat.com/errata/RHSA-2025:13933 ; https://alas.aws.amazon.com/AL2/ALAS2-2025-2941.html ; https://linux.oracle.com/errata/ELSA-2025-11534.html ; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48384 ; https://nvd.nist.gov/vuln/detail/CVE-2025-48384","cwes":"CWE-59,CWE-436","catalogVersion":"2026.10.02","updated_at":"2026-10-02 15:58:10"},"epss":{"cve_year":"2025","cve_id":"48384","cve":"CVE-2025-48384","epss":"0.042000000","percentile":"0.906510000","score_date":"2026-10-02","updated_at":"2026-10-03 00:13:27"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-48384","options":[{"Exploitation":"active"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-08-26T03:55:23.181071Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2025-08-25","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48384"},"type":"kev"}}],"providerMetadata":{"dateUpdated":"2026-02-26T17:51:05.174Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48384"}],"timeline":[{"lang":"en","time":"2025-08-25T00:00:00.000Z","value":"CVE-2025-48384 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2025-11-04T21:11:00.255Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00003.html"},{"url":"http://seclists.org/fulldisclosure/2025/Sep/60"},{"url":"http://www.openwall.com/lists/oss-security/2025/07/08/4"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"git","vendor":"git","versions":[{"status":"affected","version":"< 2.43.7"},{"status":"affected","version":">= 2.44.0-rc0, < 2.44.4"},{"status":"affected","version":">= 2.45.0-rc0, < 2.45.4"},{"status":"affected","version":">= 2.46.0-rc0, < 2.46.4"},{"status":"affected","version":">= 2.47.0-rc0, < 2.47.3"},{"status":"affected","version":">= 2.48.0-rc0, < 2.48.2"},{"status":"affected","version":">= 2.49.0-rc0, < 2.49.1"},{"status":"affected","version":">= 2.50.0-rc0, < 2.50.1"}]}],"descriptions":[{"lang":"en","value":"Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-436","description":"CWE-436: Interpretation Conflict","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-07-08T18:23:48.710Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9"}],"source":{"advisory":"GHSA-vwqx-4fm8-6qc9","discovery":"UNKNOWN"},"title":"Git allows arbitrary code execution through broken config quoting"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2025-48384","datePublished":"2025-07-08T18:23:48.710Z","dateReserved":"2025-05-19T15:46:00.397Z","dateUpdated":"2026-02-26T17:51:05.174Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-07-08 19:15:42","lastModifiedDate":"2026-09-24 13:10:00","problem_types":["CWE-59","CWE-436","CWE-436 CWE-436: Interpretation Conflict","CWE-59 CWE-59: Improper Link Resolution Before File Access ('Link Following')"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","baseScore":8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.3,"impactScore":6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-08-26T03:55:23.181071Z","id":"CVE-2025-48384","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionEndExcluding":"2.43.7","matchCriteriaId":"BB276680-D286-4DF6-BCB7-CAC1D9D77E08"},{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionStartIncluding":"2.44.0","versionEndExcluding":"2.44.4","matchCriteriaId":"856A8970-74E2-4F8F-A1A6-2AB1C0C87E45"},{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionStartIncluding":"2.45.0","versionEndExcluding":"2.45.4","matchCriteriaId":"6D1DB9BA-3D91-4F7D-931E-A664737129F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionStartIncluding":"2.46.0","versionEndExcluding":"2.46.4","matchCriteriaId":"01BDA55C-F398-4286-ABC6-979A783BDC65"},{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionStartIncluding":"2.47.0","versionEndExcluding":"2.47.3","matchCriteriaId":"FF4A2ACC-0996-4869-884D-734D6006C032"},{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionStartIncluding":"2.48.0","versionEndExcluding":"2.48.2","matchCriteriaId":"0DD21A83-8D62-4EE4-914B-B5ACA19A84A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionStartIncluding":"2.49.0","versionEndExcluding":"2.49.1","matchCriteriaId":"95C1825C-B7A2-46E9-93D7-2D196DB2515E"},{"vulnerable":true,"criteria":"cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*","versionStartIncluding":"2.50.0","versionEndExcluding":"2.50.1","matchCriteriaId":"18F948AD-22C0-4B2E-B497-899F3A94B70A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","matchCriteriaId":"FA6FEEC2-9F11-4643-8827-749718254FED"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*","versionEndExcluding":"26.0","matchCriteriaId":"37CC7F40-CC3A-4AEB-9260-B621FE64735A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"48384","Ordinal":"1","Title":"Git allows arbitrary code execution through broken config quotin","CVE":"CVE-2025-48384","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"48384","Ordinal":"1","NoteData":"Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.","Type":"Description","Title":"Git allows arbitrary code execution through broken config quotin"}]}}}