🛡️ CVE-2018-10859 — git-annex
Description
git-annex GPG decryption attack via compromised remote
# *git-annex* GPG decryption attack via compromised remote
A malicious server for a special remote could trick git-annex into
decrypting a file that was encrypted to the user's GPG key. This
attack could be used to expose encrypted data that was never stored
in *git-annex*. Daniel Dent discovered this attack in collaboration
with Joey Hess.
To perform this attack the attacker needs control of a server
hosting an *encrypted* special remote used by the victim's
*git-annex* repository. The attacker uses `git annex addurl
--relaxed` with an innocuous URL, and waits for the user's
git-annex to download it, and upload an (encrypted) copy to the
special remote they also control. At some later point, when the
user downloads the content from the special remote, the attacker
instead sends them the content of the GPG-encrypted file that they
wish to have decrypted in its place (which may have been exfiltrated
from the victim's system via the attack described in
HSEC-2023-0010 / CVE-2018-10857, or acquired by other
means). Finally, the attacker drops their own copy of the original
innocuous URL, and waits for the victim git-annex to send them the
accidentially decrypted file.
The issue was fixed by making git-annex refuse to download
encrypted content from special remotes, unless it knows the hash of
the expected content. When the attacker provides some other
GPG-encrypted content, it will fail the hash check and be discarded.
Affected software
CVE-2018-10859 is recorded against 1 package.
- git-annex (from 0.20110417 up to 6.20180626)
Timeline and source
Published on 14 November 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| git-annex | 0.20110417 | 6.20180626 |
References
Similar Threats
- Unknown openSUSE-SU-2026:11087-1
- Unknown CVE-2014-6274
- Unknown CVE-2017-12976
- Unknown CVE-2018-10857
- Unknown HSEC-2023-0012
More CVE 2018 advisories
Browse all of CVE 2018 in the advisory index.
Free Vulnerability Check
Is your site affected by CVE-2018-10859?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2018-10859 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.