Skip to content

GHSA-cw77-j82w-mchm on CTRL-OS 26.05

Aliases: GHSA-cw77-j82w-mchm, CVE-2026-53584

Packages: libgit2

Status: Plausible

Advisory Information

Impact

A crafted repository with a submodule whose path contains traversal components (e.g. "../") can cause the library to create directories outside the repository's working tree.

Users of libgit2 who initialize a submodule in a crafted repository will be affected.

Patches

This is patched in libgit2 v1.9.5 and v1.8.6.

Credits

This issue was responsibly disclosed by Michał Majchrowicz and Marcin Wyczechowski, members of the AFINE Team.

Updates

2026-08-21 15:50 CEST

Metadata changes:

  • Status for package libgit2: “Plausible

2026-08-21 15:43 CEST

Metadata changes:

  • Status for package libgit2: “New