🛡️ CVE-2024-35186 — gitoxide

🟠 CVSS 8.8 — High ✅ No Known Exploit CWE-22 NVD
8.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

gix traversal outside working tree enables arbitrary code execution

Summary

During checkout, gitoxide does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application.

Details

Although gix-worktree-state checks for collisions with existing files, it does not itself check if a path is really in the working tree when performing a checkout, nor do the path checks in gix-fs and gix-worktree prevent this. Cloning an untrusted repository containing specially crafted tree or blob names will create new files outside the repository, or inside the repository or a submodule's .git directory. The simplest cases are:

  • A tree named .. to traverse upward. This facilitates arbitrary code execution because files can be placed in one or more locations where they are likely to be executed soon.
  • A tree named .git to enter a .git directory. This facilitates arbitrary code execution because hooks can be installed.

A number of alternatives that achieve the same effect are also possible, some of which correspond to specific vulnerabilities that have affected Git in the past:

  • A tree or blob whose name contains one or more /, to traverse upward or downward. For example, even without containing any tree named .. or .git, a repository can represent a file named ../outside or .git/hooks/pre-commit. This is distinct from the more intuitive case a repository containing trees that represent those paths.
  • In Windows, a tree or blob whose name contains one or more \, to traverse upward or downward. (Unlike /, these are valid on other systems.) See [GHSA-xjx4-8694-q2fq](https://github.com/git/git/security/advisories/GHSA-xjx4-8694-q2fq).
  • On a case-insensitive filesystem (such as NTFS, APFS, or HFS+), a tree named as a case variant of .git.
  • On HFS+, a tree named like .git or a case variant, with characters added that HFS+ ignores [in collation](https://developer.apple.com/library/archive/technotes/tn/tn1150.html#StringComparisonAlgorithm). See https://github.com/git/git/commit/6162a1d323d24fd8cbbb1a6145a91fb849b2568f.
  • On NTFS, a tree equivalent to .git (or a case variant) by the use of [NTFS stream](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-fscc/c54dec26-1551-4d3a-a0ea-4fa40f848eb3) notation, such as .git::$INDEX_ALLOCATION. See [GHSA-5wph-8frv-58vj](https://github.com/git/git/security/advisories/GHSA-5wph-8frv-58vj).
  • On an NTFS volume with [8.3 aliasing](https://learn.microsoft.com/en-us/windows/win32/fileio/naming-a-file#short-vs-long-names) enabled, a tree named as git~1 (or a case variant). See [GHSA-589j-mmg9-733v](https://github.com/git/git/security/advisories/GHSA-589j-mmg9-733v).

When a checkout creates some files outside the repository directory but fails to complete, the repository directory is usually removed, but the outside files remain.

PoC

For simplicity, these examples stage a stand-in file with a valid name, modify the index, and commit. The instructions assume sed supports -i, which is the case on most systems. If using Windows, a Git Bash shell should be used.

Example: Downward traversal to install hooks

1. Create a new repository with git init dangerous-repo-installs-hook and cd into the directory.

2. Create the stand-in called .git@hooks@pre-commit, with the *contents*:

```sh

#!/bin/sh

printf 'Vulnerable!\n'

date >vulnerable

```

3. Stage the stand-in: git add --chmod=+x .git@hooks@pre-commit

4. Edit the index: env LC_ALL=C sed -i.orig 's|\.git@hooks@pre-commit|.git/hooks/pre-commit|' .git/index

5. Commit: git commit -m 'Initial commit'

6. *Optionally*, push to a private remote.

Then, on another or the same machine:

1. Clone the repository with a gix clone … command.

2. Enter the newly created directory.

3. *Optionally* run ls -l .git/hooks to observe that the pre-commit hook is already present.

4. Make a new file and commit it with git. This causes the payload surreptitiously installed as a pre-commit hook to run, printing the message Vulnerable! and creating a file in the current directory containing the current date and time.

Note that the effect is not limited to modifying the current directory. The payload could be written to perform any action that the user who runs git commit is capable of.

Example: Upward traversal to create a file above the working tree

1. Create a new repository with git init dangerous-repo-reaches-up, and cd into the directory.

2. Create the stand-in: echo 'A file outside the working tree, somehow.' >..@outside

3. Stage the stand-in: git add ..@outside

4. Edit the index: env LC_ALL=C sed -i.orig 's|\.\.@outside|../outside|' .git/index

5. Commit: git commit -m 'Initial commit'

6. *Optionally*, push to a private remote.

Then, as above, on the same or another machine, clone the repository with a gix clone … command. Observe t

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Weakness class

CVE-2024-35186 is classified as CWE-22: Path Traversal. A file path built from user input is not confined to the intended directory, letting an attacker reach files elsewhere on the filesystem.

Affected software

CVE-2024-35186 is recorded against 8 packages.

  • gitoxide
  • gitoxide-core
  • gix
  • gix-fs
  • gix-index
  • gix-worktree
  • gix-worktree-state
  • unknown

Timeline and source

Published on 22 May 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Package)
rustsec.org (Web)
rustsec.org (Web)

CVE-2024-35186 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity HIGH
CVSS Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE CWE-22
Public Exploit ✅ No
Source NVD
Published 2024-05-22
Updated 2026-08-12
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
gitoxide
gitoxide-core
gix
gix-fs
gix-index
gix-worktree
gix-worktree-state
unknown

Site Security Check

Is gitoxide part of your stack?

CVE-2024-35186 is rated CVSS 8.8 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2024