go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.
CVSS Details
- CVSS 4.0 Base Score: 9.2 (CRITICAL)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear)
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafanaUpgrade grafana-selinux | Jan 21, 2025 | Jan 6, 2025 |
| Amazon Linux Ami 2 | — | Upgrade amazon-ssm-agent | Feb 5, 2025 | Jan 6, 2025 |
| Amazon_linux_2023 | — | Upgrade amazon-ssm-agent | Feb 17, 2025 | Jan 6, 2025 |
| Debian | — | No solution existsUpgrade golang-github-go-git-go-git | May 15, 2025 | Jan 6, 2025 |
| Oracle_linux | — | Upgrade grafana-selinuxUpgrade grafana | Jan 20, 2025 | Jan 6, 2025 |
| Redhat_linux | — | Upgrade grafana-debugsourceUpgrade grafana-selinuxUpgrade grafanaUpgrade grafana-debuginfo | Jan 22, 2025 | Jan 6, 2025 |
| Rocky_linux | — | Upgrade grafana-debuginfoUpgrade grafanaUpgrade grafana-selinuxUpgrade grafana-debugsource | Feb 14, 2025 | Jan 6, 2025 |
| Suse | — | Upgrade rime-schema-wugniuUpgrade rime-schema-middle-chineseUpgrade amazon-ssm-agentUpgrade rime-schema-allUpgrade grafanaUpgrade rime-schema-quickUpgrade govulncheck-vulndbUpgrade rime-schema-soutzoeUpgrade rime-schema-strokeUpgrade rime-schema-bopomofoUpgrade rime-schema-combo-pinyinUpgrade rime-schema-luna-pinyinUpgrade rime-schema-terra-pinyinUpgrade rime-schema-pinyin-simpUpgrade rime-schema-ipaUpgrade rime-schema-wubiUpgrade rime-schema-cantoneseUpgrade rime-schema-essay-simpUpgrade rime-schema-preludeUpgrade rime-schema-customUpgrade trivyUpgrade rime-schema-extraUpgrade rime-schema-cangjieUpgrade rime-schema-double-pinyinUpgrade rime-schema-stenotypeUpgrade rime-schema-defaultUpgrade rime-schema-scjUpgrade rime-schema-essayUpgrade rime-schema-emojiUpgrade rime-schema-array | Jan 13, 2025 | Jan 6, 2025 |
| Ubuntu | — | Upgrade go-git (Ubuntu Pro)Upgrade golang-github-go-git-go-git-dev (Ubuntu Pro) | Mar 13, 2026 | Jan 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub