Vulnerability record · CVE-2025-48384 · published 8 July 2025
CVE-2025-48384: Git config CRLF handling allows submodule path link-following code execution
Git Scm · Git
Git mishandles trailing carriage returns when writing config values, so a submodule path ending in CR is read back altered during submodule initialization. If a symlink points that altered path at the submodule hooks directory and the submodule ships an executable post-checkout hook, that hook runs after checkout. Fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1 and v2.50.1.
Description
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.0 high severity, CISA KEV listing with a remediation deadline, and code execution potential, though exploitation requires user interaction and a crafted repository.
What it is
Git mishandles trailing carriage returns when writing config values, so a submodule path ending in CR is read back altered during submodule initialization. If a symlink points that altered path at the submodule hooks directory and the submodule ships an executable post-checkout hook, that hook runs after checkout. Fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1 and v2.50.1.
Impact
An attacker who controls a repository and its submodule content can cause arbitrary code from a post-checkout hook to execute in the victim's environment, giving code execution in the context of the user running the Git operation.
Attack surface
Reached over the network by cloning or initializing a crafted repository with a malicious submodule path; the CVSS vector indicates low privileges and required user interaction, so the victim must perform the checkout/init action.
Exploitation
Listed in CISA KEV with a 2025-08-25 addition and 2025-09-15 remediation due date, indicating known exploitation; EPSS 30-day probability is about 4.1 percent (90th percentile). No ransomware campaign use is documented.
What to do
- Upgrade Git to v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, v2.50.1 or later; apply vendor patches for Debian and Apple Xcode builds.
- Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use where no mitigation exists.
- Avoid initializing or checking out submodules from untrusted repositories until patched.
- Audit repositories and submodule paths for trailing carriage returns or unexpected symlinks into hooks directories.
Detection
- Search repository configs and submodule paths for trailing CR characters or unusual symlinks pointing into .git/hooks or submodule hook directories.
- Monitor for unexpected execution of post-checkout hooks during clone or submodule init, especially from newly fetched repositories.
- Alert on Git versions below the fixed releases in CI/CD and developer endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-48384 to the Known Exploited Vulnerabilities catalog on 25 August 2025 as "Git Link Following Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 15 September 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9 | Vendor Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/60 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/07/08/4 | Mailing List |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00003.html | Mailing ListThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48384 | US Government Resource |
Track CVE-2025-48384 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-48384), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.