gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout

cve CVE-2026-100419 3 sources, 4 claims · Watch

Red Hat writes:
gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsgitoxidelabs/gitoxide
NVD says “GitoxideLabs · gitoxide”
made_bygitoxidelabs
NVD says “GitoxideLabs”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
GitHub advisories7
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

—
Cvss
cvss
NVD7
receipt
Source
NVD
Its words
7.0
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:39 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:cargo/gix-fs",
            "product": "gitoxide",
            "vendor": "GitoxideLabs",
            "versions": [
              {
                "lessThan": "0.23.0",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "0.23.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the worktree through the symlink for code execution or file manipulation."
      }
    ],
    "id": "CVE-2026-100419",
    "lastModified": "2026-09-28T14:17:09.210",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.0,
          "impactScore": 5.9,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "PASSIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-100419",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-28T13:05:49.724852Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-25T22:17:10.613",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/blob/gix-fs-v0.22.1/gix-fs/src/stack.rs#L185-L196"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/gitoxide-gix-fs-before-0.23.0-worktree-escape-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
Red Hat7
receipt
Source
Red Hat
Its words
7.0
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-100419",
  "CWE": "CWE-59",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2541673",
  "bugzilla_description": "gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout",
  "cvss3_score": "7.0",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-25T22:04:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-100419.json",
  "severity": "moderate"
}
—
Cwe
cwe
GitHub advisoriesCWE-59
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

—
Cwe
cwe
Red HatCWE-59
receipt
Source
Red Hat
Its words
CWE-59
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-100419",
  "CWE": "CWE-59",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2541673",
  "bugzilla_description": "gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout",
  "cvss3_score": "7.0",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-25T22:04:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-100419.json",
  "severity": "moderate"
}
—
Product
product
NVDgitoxide
receipt
Source
NVD
Its words
gitoxide
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
2026-09-29 17:49 UTCgitoxide
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:cargo/gix-fs",
            "product": "gitoxide",
            "vendor": "GitoxideLabs",
            "versions": [
              {
                "lessThan": "0.23.0",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "0.23.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the worktree through the symlink for code execution or file manipulation."
      }
    ],
    "id": "CVE-2026-100419",
    "lastModified": "2026-09-28T14:17:09.210",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.0,
          "impactScore": 5.9,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "PASSIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-100419",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-28T13:05:49.724852Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-25T22:17:10.613",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/blob/gix-fs-v0.22.1/gix-fs/src/stack.rs#L185-L196"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/gitoxide-gix-fs-before-0.23.0-worktree-escape-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisorieshigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

—
Severity
severity
conflict
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-100419",
  "CWE": "CWE-59",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2541673",
  "bugzilla_description": "gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout",
  "cvss3_score": "7.0",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-09-25T22:04:00Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-100419.json",
  "severity": "moderate"
}
medium
Status
status
NVDDeferred
receipt
Source
NVD
Its words
Deferred
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:39 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:cargo/gix-fs",
            "product": "gitoxide",
            "vendor": "GitoxideLabs",
            "versions": [
              {
                "lessThan": "0.23.0",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "0.23.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the worktree through the symlink for code execution or file manipulation."
      }
    ],
    "id": "CVE-2026-100419",
    "lastModified": "2026-09-28T14:17:09.210",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.0,
          "impactScore": 5.9,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "PASSIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-100419",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-28T13:05:49.724852Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-25T22:17:10.613",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/blob/gix-fs-v0.22.1/gix-fs/src/stack.rs#L185-L196"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/gitoxide-gix-fs-before-0.23.0-worktree-escape-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDGitoxideLabs
receipt
Source
NVD
Its words
GitoxideLabs
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
2026-09-29 17:49 UTCGitoxideLabs
2026-09-29 09:39 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:cargo/gix-fs",
            "product": "gitoxide",
            "vendor": "GitoxideLabs",
            "versions": [
              {
                "lessThan": "0.23.0",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "0.23.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the worktree through the symlink for code execution or file manipulation."
      }
    ],
    "id": "CVE-2026-100419",
    "lastModified": "2026-09-28T14:17:09.210",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.0,
          "impactScore": 5.9,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "PASSIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-100419",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-28T13:05:49.724852Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-25T22:17:10.613",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/blob/gix-fs-v0.22.1/gix-fs/src/stack.rs#L185-L196"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/gitoxide-gix-fs-before-0.23.0-worktree-escape-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-f89h-2fjh-2r9q"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout
zetlyn/cve-redhat · 2026-09-25
cvss 7 cwe CWE-59 severity moderate source
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the worktree through the symlink for code execution or file manipulation.
zetlyn/cve-nvd · 2026-09-25
cvss 7 product gitoxide status Deferred vendor GitoxideLabs source
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree...
zetlyn/cve-ghsa · 2026-09-26
cvss 7 cwe CWE-59 severity high source
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree...
zetlyn/cve-ghsa · 2026-09-26
cvss 7 cwe CWE-59 severity high source