


Perceptive Security
SOC/SIEM Consultancy

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata…
Published:
28 augustus 2026 om 00:00:00
Alert date:
28 augustus 2026 om 21:07:46
Source:
nvd.nist.gov
Supply Chain & Dependencies, Zero-Day Vulnerabilities
CVE-2026-82252 affects gitoxide versions before 0.52.1, a Rust-based Git implementation. The vulnerability arises because gitoxide follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject arbitrary external content into submodule metadata. An attacker can craft a malicious repository where .gitmodules is a symlink pointing outside the repository tree. When gitoxide parses this file, it processes attacker-controlled content as legitimate submodule configuration. This exposes arbitrary name, path, and URL values that could be used to manipulate submodule behavior. The issue represents a repository boundary violation, a class of vulnerability also seen in other Git implementations. Users are advised to upgrade to gitoxide 0.52.1 or later to remediate the issue.
Technical details
Mitigation steps:
Affected products:
gitoxide
gitoxide before 0.52.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82252
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-pg4w-g64p-qwhj
https://www.vulncheck.com/advisories/gitoxide-before-0.52.1-repository-boundary-violation-via-symlinked-gitmodules
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
