The Git link-following flaw: cloning a repository writes a file where it should not
A repository can be crafted so that cloning it writes outside the directory being cloned into. CISA added it to the Known Exploited catalogue in August 2025.
A fixed package version is available on 6 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
Git mishandles a symbolic link while checking out a crafted repository, following it rather than refusing, so a file lands at a path the repository chose instead of inside the working tree.
What an attacker gets: Arbitrary file write as the user running git, which in a checkout directory usually means a hook script that runs on the next git operation, which means code execution.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- It needs you to clone or check out a repository you do not control. The classic setting is CI, where a build agent clones whatever it is pointed at.
- Recursive clones widen it, because a submodule names its own source.
- A server that only pulls from repositories your own team writes is a much smaller target than a build agent that clones on request.
Check your own server
git --version && git config --global --get core.symlinksThe version, and whether symlink handling has been altered. Build agents are where to check first.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | git | Fixed | 1:2.34.1-1ubuntu1.13 |
| Ubuntu 24.04 LTS | git | Fixed | 1:2.43.0-1ubuntu7.3 |
| Debian 12 (bookworm) | git | Fixed | 1:2.39.5-0+deb12u3 |
| Debian 13 (trixie) | git | Fixed | 1:2.47.3-0+deb13u1 |
| Rocky Linux 9 | git | Fixed | 0:2.47.3-1.el9_6 |
| AlmaLinux 9 | git | Fixed | 2.47.3-1.el9_6 |
Install the fix with apt update && apt install --only-upgrade git on Debian and Ubuntu, or dnf update git on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
Recorded from nvd. Its weakness class is CWE-59 and CWE-436, from NVD.
- https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9
- http://seclists.org/fulldisclosure/2025/Sep/60
- http://www.openwall.com/lists/oss-security/2025/07/08/4
- https://lists.debian.org/debian-lts-announce/2025/10/msg00003.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48384
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2025-48384 included. It changes nothing.