← Vulnerability feed

Vulnerability record · CVE-2025-48384 · published 8 July 2025

CVE-2025-48384: Git config CRLF handling allows submodule path link-following code execution

Git Scm · Git

Git mishandles trailing carriage returns when writing config values, so a submodule path ending in CR is read back altered during submodule initialization. If a symlink points that altered path at the submodule hooks directory and the submodule ships an executable post-checkout hook, that hook runs after checkout. Fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1 and v2.50.1.

8.0 CVSS 3.1 High CISA KEV since 25 Aug 2025 EPSS 4.1% · top 9.6% CWE-59 · Link followingCWE-436 · Interpretation conflict
8.0CVSS 3.1 base score
4.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References
24 Sep 2026Last modified by NVD

Description

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.0 high severity, CISA KEV listing with a remediation deadline, and code execution potential, though exploitation requires user interaction and a crafted repository.

What it is

Git mishandles trailing carriage returns when writing config values, so a submodule path ending in CR is read back altered during submodule initialization. If a symlink points that altered path at the submodule hooks directory and the submodule ships an executable post-checkout hook, that hook runs after checkout. Fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1 and v2.50.1.

Impact

An attacker who controls a repository and its submodule content can cause arbitrary code from a post-checkout hook to execute in the victim's environment, giving code execution in the context of the user running the Git operation.

Attack surface

Reached over the network by cloning or initializing a crafted repository with a malicious submodule path; the CVSS vector indicates low privileges and required user interaction, so the victim must perform the checkout/init action.

Exploitation

Listed in CISA KEV with a 2025-08-25 addition and 2025-09-15 remediation due date, indicating known exploitation; EPSS 30-day probability is about 4.1 percent (90th percentile). No ransomware campaign use is documented.

What to do

  • Upgrade Git to v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, v2.50.1 or later; apply vendor patches for Debian and Apple Xcode builds.
  • Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use where no mitigation exists.
  • Avoid initializing or checking out submodules from untrusted repositories until patched.
  • Audit repositories and submodule paths for trailing carriage returns or unexpected symlinks into hooks directories.

Detection

  • Search repository configs and submodule paths for trailing CR characters or unusual symlinks pointing into .git/hooks or submodule hook directories.
  • Monitor for unexpected execution of post-checkout hooks during clone or submodule init, especially from newly fetched repositories.
  • Alert on Git versions below the fixed releases in CI/CD and developer endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-48384 to the Known Exploited Vulnerabilities catalog on 25 August 2025 as "Git Link Following Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 15 September 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-48384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-48384), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.