🛡️ CVE-2024-35186 — gitoxide
Description
gix traversal outside working tree enables arbitrary code execution
Summary
During checkout, gitoxide does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application.
Details
Although gix-worktree-state checks for collisions with existing files, it does not itself check if a path is really in the working tree when performing a checkout, nor do the path checks in gix-fs and gix-worktree prevent this. Cloning an untrusted repository containing specially crafted tree or blob names will create new files outside the repository, or inside the repository or a submodule's .git directory. The simplest cases are:
- A tree named
..to traverse upward. This facilitates arbitrary code execution because files can be placed in one or more locations where they are likely to be executed soon. - A tree named
.gitto enter a.gitdirectory. This facilitates arbitrary code execution because hooks can be installed.
A number of alternatives that achieve the same effect are also possible, some of which correspond to specific vulnerabilities that have affected Git in the past:
- A tree or blob whose name contains one or more
/, to traverse upward or downward. For example, even without containing any tree named..or.git, a repository can represent a file named../outsideor.git/hooks/pre-commit. This is distinct from the more intuitive case a repository containing trees that represent those paths. - In Windows, a tree or blob whose name contains one or more
\, to traverse upward or downward. (Unlike/, these are valid on other systems.) See [GHSA-xjx4-8694-q2fq](https://github.com/git/git/security/advisories/GHSA-xjx4-8694-q2fq). - On a case-insensitive filesystem (such as NTFS, APFS, or HFS+), a tree named as a case variant of
.git. - On HFS+, a tree named like
.gitor a case variant, with characters added that HFS+ ignores [in collation](https://developer.apple.com/library/archive/technotes/tn/tn1150.html#StringComparisonAlgorithm). See https://github.com/git/git/commit/6162a1d323d24fd8cbbb1a6145a91fb849b2568f. - On NTFS, a tree equivalent to
.git(or a case variant) by the use of [NTFS stream](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fscc/c54dec26-1551-4d3a-a0ea-4fa40f848eb3) notation, such as.git::$INDEX_ALLOCATION. See [GHSA-5wph-8frv-58vj](https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vj). - On an NTFS volume with [8.3 aliasing](https://learn.microsoft.com/en-us/windows/win32/fileio/naming-a-file#short-vs-long-names) enabled, a tree named as
git~1(or a case variant). See [GHSA-589j-mmg9-733v](https://github.com/git/git/security/advisories/GHSA-589j-mmg9-733v).
When a checkout creates some files outside the repository directory but fails to complete, the repository directory is usually removed, but the outside files remain.
PoC
For simplicity, these examples stage a stand-in file with a valid name, modify the index, and commit. The instructions assume sed supports -i, which is the case on most systems. If using Windows, a Git Bash shell should be used.
Example: Downward traversal to install hooks
1. Create a new repository with git init dangerous-repo-installs-hook and cd into the directory.
2. Create the stand-in called .git@hooks@pre-commit, with the *contents*:
```sh
#!/bin/sh
printf 'Vulnerable!\n'
date >vulnerable
```
3. Stage the stand-in: git add --chmod=+x .git@hooks@pre-commit
4. Edit the index: env LC_ALL=C sed -i.orig 's|\.git@hooks@pre-commit|.git/hooks/pre-commit|' .git/index
5. Commit: git commit -m 'Initial commit'
6. *Optionally*, push to a private remote.
Then, on another or the same machine:
1. Clone the repository with a gix clone … command.
2. Enter the newly created directory.
3. *Optionally* run ls -l .git/hooks to observe that the pre-commit hook is already present.
4. Make a new file and commit it with git. This causes the payload surreptitiously installed as a pre-commit hook to run, printing the message Vulnerable! and creating a file in the current directory containing the current date and time.
Note that the effect is not limited to modifying the current directory. The payload could be written to perform any action that the user who runs git commit is capable of.
Example: Upward traversal to create a file above the working tree
1. Create a new repository with git init dangerous-repo-reaches-up, and cd into the directory.
2. Create the stand-in: echo 'A file outside the working tree, somehow.' >..@outside
3. Stage the stand-in: git add ..@outside
4. Edit the index: env LC_ALL=C sed -i.orig 's|\.\.@outside|../outside|' .git/index
5. Commit: git commit -m 'Initial commit'
6. *Optionally*, push to a private remote.
Then, as above, on the same or another machine, clone the repository with a gix clone … command. Observe t
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.
Weakness class
CVE-2024-35186 is classified as CWE-22: Path Traversal. A file path built from user input is not confined to the intended directory, letting an attacker reach files elsewhere on the filesystem.
Affected software
CVE-2024-35186 is recorded against 8 packages.
- gitoxide
- gitoxide-core
- gix
- gix-fs
- gix-index
- gix-worktree
- gix-worktree-state
- unknown
Timeline and source
Published on 22 May 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.
References
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Package)
rustsec.org (Web)
rustsec.org (Web)
CVE-2024-35186 on other distributions
Each distribution ships its own build and its own fixed version. Pick the one you run:
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| gitoxide | — | — |
| gitoxide-core | — | — |
| gix | — | — |
| gix-fs | — | — |
| gix-index | — | — |
| gix-worktree | — | — |
| gix-worktree-state | — | — |
| unknown | — | — |
References
Similar Threats
- Unknown openSUSE-SU-2026:11474-1
- High GHSA-fr8x-3vfx-f45h
- High GHSA-pg4w-g64p-qwhj
- Unknown openSUSE-SU-2025:14994-1
- Medium CVE-2025-31130
Site Security Check
Is gitoxide part of your stack?
CVE-2024-35186 is rated CVSS 8.8 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.