GHSA-cw77-j82w-mchm on CTRL-OS 26.05
Aliases: GHSA-cw77-j82w-mchm, CVE-2026-53584
Packages: libgit2
Status: Plausible
Advisory Information
Impact
A crafted repository with a submodule whose path contains traversal components (e.g. "../") can cause the library to create directories outside the repository's working tree.
Users of libgit2 who initialize a submodule in a crafted repository will be affected.
Patches
This is patched in libgit2 v1.9.5 and v1.8.6.
Credits
This issue was responsibly disclosed by Michał Majchrowicz and Marcin Wyczechowski, members of the AFINE Team.
Updates
2026-08-21 15:50 CEST
Metadata changes:
- Status for package
libgit2: “Plausible”
2026-08-21 15:43 CEST
Metadata changes:
- Status for package
libgit2: “New”