🛡️ CVE-2018-10859 — git-annex

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

git-annex GPG decryption attack via compromised remote

# *git-annex* GPG decryption attack via compromised remote

A malicious server for a special remote could trick git-annex into

decrypting a file that was encrypted to the user's GPG key. This

attack could be used to expose encrypted data that was never stored

in *git-annex*. Daniel Dent discovered this attack in collaboration

with Joey Hess.

To perform this attack the attacker needs control of a server

hosting an *encrypted* special remote used by the victim's

*git-annex* repository. The attacker uses `git annex addurl

--relaxed` with an innocuous URL, and waits for the user's

git-annex to download it, and upload an (encrypted) copy to the

special remote they also control. At some later point, when the

user downloads the content from the special remote, the attacker

instead sends them the content of the GPG-encrypted file that they

wish to have decrypted in its place (which may have been exfiltrated

from the victim's system via the attack described in

HSEC-2023-0010 / CVE-2018-10857, or acquired by other

means). Finally, the attacker drops their own copy of the original

innocuous URL, and waits for the victim git-annex to send them the

accidentially decrypted file.

The issue was fixed by making git-annex refuse to download

encrypted content from special remotes, unless it knows the hash of

the expected content. When the attacker provides some other

GPG-encrypted content, it will fail the hash check and be discarded.

Affected software

CVE-2018-10859 is recorded against 1 package.

  • git-annex (from 0.20110417 up to 6.20180626)

Timeline and source

Published on 14 November 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

git-annex.branchable.com (Advisory)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-11-14
Updated 2026-08-12
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
git-annex 0.20110417 6.20180626

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2018-10859?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2018-10859 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.