CVE-2026-71556
published 2026-08-07CVE-2026-71556: go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and…
PriorityP337high7.1CVSS 3.1
AVNACLPRNUIRSUCNIHAL
EPSS
0.45%
36.8th percentile
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | go-git_go-git_v5 | >= 0 < 5.19.2 | 5.19.2 |
| github.com | go-git_go-git_v6 | >= 0 < 6.0.0-alpha.5 | 6.0.0-alpha.5 |
| go-git | go-git | < 5.19.2 | 5.19.2 |
| go-git | go-git | — | — |
| multicluster-engine | assisted-installer-controller-rhel9 | — | — |
| multicluster-engine | assisted-service-9-rhel9 | — | — |
| multicluster-engine | cluster-image-set-controller-rhel9 | — | — |
| multicluster-engine | must-gather-rhel9 | — | — |
| rhacm2 | acm-must-gather-rhel9 | — | — |
| rhacm2 | multicluster-operators-subscription-rhel9 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
go-git up to 5.19.1/6.0.0-alpha.4 Worktree Operations path traversal
vuldb·2026-08-07·CVSS 7.1
CVE-2026-71556 [HIGH] go-git up to 5.19.1/6.0.0-alpha.4 Worktree Operations path traversal
A vulnerability was found in go-git up to 5.19.1/6.0.0-alpha.4 and classified as critical. This affects an unknown part of the component Worktree Operations. The manipulation results in path traversal.
This vulnerability was named CVE-2026-71556. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
go-git: Worktree operations may follow symlinks
ghsa·2026-08-07
CVE-2026-71556 [HIGH] CWE-59 go-git: Worktree operations may follow symlinks
go-git: Worktree operations may follow symlinks
## Impact
A symlink traversal issue in `go-git` could allow worktree operations to modify files outside the intended worktree path.
The `worktreeFilesystem` wrapper rejected dangerous path strings, including paths containing `.git`, parent-directory components, or control characters. However, it did not prevent filesystem operations from following symbolic links that were already present in the worktree.
As a result, a path that is safe when evaluated as a string could still resolve into the repository's Git metadata directory. For example, if `s` is a symbolic link to `.git`, writing to `s/config` would modify `.git/config`.
A symbolic link at the final path component could also be followed. For example, if `s` points directly to `.git/
Red Hat
github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
vendor_redhat·2026-08-07·CVSS 7.1
CVE-2026-71556 [HIGH] CWE-59 github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.
A flaw was found in go-git, an extensible Git implementation library. Worktree operations, such as checkout, status, and add, resolve symbolic links within the working tree without proper bound
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-71556 golang-github-git-5: go-git: Arbitrary file read/write via symbolic link resolution [fedora-all]
bugzilla·2026-08-26·CVSS 7.1
CVE-2026-71556 [HIGH] CVE-2026-71556 golang-github-git-5: go-git: Arbitrary file read/write via symbolic link resolution [fedora-all]
CVE-2026-71556 golang-github-git-5: go-git: Arbitrary file read/write via symbolic link resolution [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree opera
Bugzilla
CVE-2026-71556 github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
bugzilla·2026-08-07·CVSS 7.1
CVE-2026-71556 [HIGH] CVE-2026-71556 github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
CVE-2026-71556 github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.
https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aabhttps://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07achttps://github.com/go-git/go-git/releases/tag/v5.19.2https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm
2026-08-07
Published