← Vulnerability feed

Vulnerability record · CVE-2020-27955 · published 5 November 2020

CVE-2020-27955: Git LFS uncontrolled search path enables remote code execution

GGit Large File Storage Project · Git Large File Storage

Git LFS 2.12.0 contains an uncontrolled search path element (CWE-427) that allows remote code execution. The record gives no further detail on the exact loading mechanism, but the flaw is network-reachable and requires no privileges or user interaction per the CVSS vector. With a 9.8 critical score and an EPSS probability above 0.82, it is a high-value target for defenders running affected Git LFS versions.

9.8 CVSS 3.1 Critical EPSS 82% · top 0.3% CWE-427 · Uncontrolled search path element
9.8CVSS 3.1 base score, v2 10.0
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 10 tagged exploit
17 Jun 2026Last modified by NVD

Description

Git LFS 2.12.0 allows Remote Code Execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references and an EPSS score above 0.82 make this an urgent patch target.

What it is

Git LFS 2.12.0 contains an uncontrolled search path element (CWE-427) that allows remote code execution. The record gives no further detail on the exact loading mechanism, but the flaw is network-reachable and requires no privileges or user interaction per the CVSS vector. With a 9.8 critical score and an EPSS probability above 0.82, it is a high-value target for defenders running affected Git LFS versions.

Impact

An attacker can execute arbitrary code in the context of the Git LFS process, gaining full control of confidentiality, integrity and availability on the host. This can lead to repository compromise, credential theft and lateral movement from developer workstations or CI runners.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N) per the CVSS vector. The uncontrolled search path means code execution is triggered through the normal Git LFS workflow rather than an explicit user action.

Exploitation

Not listed in CISA KEV, but public exploit references exist (Packet Storm, Full Disclosure, ExploitBox, legalhackers) and EPSS is 0.82715 at the 99.65th percentile, indicating active exploitation is likely. No ransomware group usage is documented in this record.

What to do

  • Upgrade Git LFS to a version later than 2.12.0; check the official release notes for the fixed build.
  • Remove or restrict write access to directories on the search path that Git LFS loads from, so untrusted files cannot be placed there.
  • Run Git LFS operations with least privilege and avoid executing it from untrusted repositories or working directories.
  • Monitor and restrict who can push to repositories processed by Git LFS in CI/CD pipelines.

Detection

  • Alert on unexpected child processes spawned by git-lfs, especially shells or scripting interpreters.
  • Monitor for new or modified executables and libraries in directories that fall on the Git LFS search path.
  • Review Git LFS version inventory across developer endpoints and CI runners to find hosts still on 2.12.0.
  • Correlate Git LFS process activity with outbound network connections to unfamiliar hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-27955 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2020-27955), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.