CVE-2025-48384
published 2025-07-08CVE-2025-48384: Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to…
high8CVSS 3.1
AVNACHPRLUIRSCCHIHAH
KEV
CISA Known Exploited Vulnerabilitydue 2025-09-15
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 26.0 | 26.0 |
| apple | xcode | — | — |
| debian | debian_linux | — | — |
| debian | git | < git 1:2.39.5-0+deb12u3 (bookworm) | git 1:2.39.5-0+deb12u3 (bookworm) |
| git-scm | git | < 2.43.7 | 2.43.7 |
| git-scm | git | >= 2.44.0 < 2.44.4 | 2.44.4 |
| git-scm | git | >= 2.45.0 < 2.45.4 | 2.45.4 |
| git-scm | git | >= 2.46.0 < 2.46.4 | 2.46.4 |
| git-scm | git | >= 2.47.0 < 2.47.3 | 2.47.3 |
| git-scm | git | >= 2.48.0 < 2.48.2 | 2.48.2 |
| git-scm | git | >= 2.49.0 < 2.49.1 | 2.49.1 |
| git-scm | git | >= 2.50.0 < 2.50.1 | 2.50.1 |
| git | git | < 2.43.7 | 2.43.7 |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | — | — |
| git | git | >= 0 < 1:2.30.2-1+deb11u5 | 1:2.30.2-1+deb11u5 |
| git | git | >= 0 < 1:2.39.5-0+deb12u3 | 1:2.39.5-0+deb12u3 |
| git | git | >= 0 < 1:2.47.3-0+deb13u1 | 1:2.47.3-0+deb13u1 |
| git | git | >= 0 < 1:2.50.1-0.1 | 1:2.50.1-0.1 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.14 | 1:2.34.1-1ubuntu1.14 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
osv8.0HIGH
vulncheck8.0HIGH
cisa8.0HIGH