CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-71556

CVE-2026-71556: Symbolic Link Directory Traversal in go-git

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 8, 2026·5 min read·63 visits

Executive Summary (TL;DR)

A path traversal vulnerability in go-git allows malicious repositories to overwrite files outside the worktree via crafted symbolic links, potentially leading to remote code execution.

A symbolic link directory traversal vulnerability was identified in go-git, a pure Go implementation of the Git specification. This vulnerability allows an attacker to construct a repository that, when checked out or processed, bypasses directory boundaries to write or overwrite arbitrary files on the host filesystem.

Vulnerability Overview

An arbitrary file write vulnerability exists in the worktree implementation of go-git, a widely integrated pure Go implementation of the Git specification. The flaw arises during repository checkout operations when processing paths containing symbolic links that resolve outside the designated worktree directory.\n\nSecurity tools, integrated development environments (IDEs), and continuous integration (CI/CD) pipelines frequently rely on go-git to programmatically clone, fetch, and analyze untrusted remote repositories. This specific vulnerability exposes these automated systems and client environments to high-severity integrity risks.\n\nThe vulnerability, cataloged as CVE-2026-71556 and GHSA-hc8v-wwc9-vgxm, represents a failure to ensure that physical paths map strictly to the intended virtual boundary. An attacker who successfully influences a repository configuration can leverage this discrepancy to execute arbitrary file operations on the host system.

Root Cause Analysis

The root cause of this vulnerability lies in the divergence between lexical path validation and physical path resolution. The worktreeFilesystem component in go-git previously restricted operations to the worktree using a string-based validation function named validPath. This function analyzed path strings to detect parent directory segments, metadata directories, and alternative filesystem stream markers.\n\nWhile lexical path checking successfully identifies direct attempts to traverse boundaries, it does not account for the state of the physical filesystem. If a repository contains a symbolic link that points to a path outside the worktree, the operating system's file creation APIs resolve the link dynamically during write operations.\n\nWhen the checkout process creates a symbolic link followed by a file situated logically beneath that link, the lexical check evaluates the second file's path string as benign. The underlying filesystem driver subsequently resolves the previously created symbolic link, which permits the file write operation to escape the root boundary of the worktree.

Code Analysis

The vulnerability is resolved by introducing active path state validation and proactive cleanup of blocking symlinks prior to file creation. The implementation introduces clearBlockingSymlinks, which recursively verifies the target path from the shallowest directory component downward.\n\ngo\nfunc (w *Worktree) clearBlockingSymlinks(name string) error {\n\tvar dirs []string\n\tfor dir := filepath.Dir(name); dir != \".\" && dir != \"\" && dir != string(filepath.Separator); dir = filepath.Dir(dir) {\n\t\tdirs = append(dirs, dir)\n\t}\n\tfor i := len(dirs) - 1; i >= 0; i-- {\n\t\tfi, err := w.Filesystem.Lstat(dirs[i])\n\t\tif err != nil {\n\t\t\tif os.IsNotExist(err) {\n\t\t\t\tcontinue\n\t\t\t}\n\t\t\treturn err\n\t\t}\n\t\tif fi.Mode()&os.ModeSymlink != 0 {\n\t\t\treturn w.Filesystem.Remove(dirs[i])\n\t\t}\n\t}\n\tfi, err := w.Filesystem.Lstat(name)\n\t// ... remaining check for final component symlink\n}\n\n\nAdditionally, the worktreeFilesystem wrapper was hardened to perform on-disk validation via validNoLeadingSymlink for every read and write operation. This ensures that any path containing a leading component that physically exists on disk as a symbolic link is rejected before passing the path to the physical driver.

Exploitation Methodology

To execute this attack, an operator must craft a repository with specific directory structures. The repository must define a symbolic link entry whose target points outside the intended worktree directory, such as the localized .git metadata directory or system configuration folders.\n\nA second file entry is then added to the repository using a logical path nested within the symbolic link component. For example, if the symbolic link is named s and points to .git, the subsequent file is defined at s/config.\n\nWhen a vulnerable client performs a checkout, the application materializes the symbolic link s. When it proceeds to write s/config, the lexical parser permits the write, and the operating system follows the symbolic link to overwrite the repository's .git/config file.\n\nmermaid\ngraph LR\n A[\"Client Clones Malicious Repo\"] --> B[\"Checkout Writes Symlink 's'\"]\n B --> C[\"Checkout Processes Path 's/config'\"]\n C --> D[\"Lexical Check Approves 's/config'\"]\n D --> E[\"OS Resolves Symlink 's' to Target\"]\n E --> F[\"Attacker Payload Overwrites Target File\"]\n

Impact Assessment

The primary consequence of this vulnerability is unauthorized file modification and absolute file write capabilities within the security context of the user executing go-git. Because Git configurations control command execution parameters, this primitive easily leads to remote code execution.\n\nBy overwriting the repository's local .git/config file, an attacker can define malicious Git configurations such as custom core pagers, file system monitors, or post-checkout hooks. These configurations are executed automatically during subsequent Git operations performed by the host environment.\n\nThe vulnerability represents a CVSS score of 7.1, indicating high severity. The main limiting factor is the requirement of user interaction, as the victim must actively clone, pull, or checkout the malicious repository to trigger the exploit.

Remediation and Security Hardening

The definitive remediation for CVE-2026-71556 requires updating the go-git library to a patched version. Maintainers have released versions 5.19.2 and 6.0.0-alpha.5 to address the flaw across affected release branches.\n\nWhere immediate patching of the underlying library is impractical, operational mitigations should be applied. Deploying Go applications within ephemeral containerized environments ensures that out-of-bounds writes do not impact the underlying host filesystem or modify persistent configuration files.\n\nAdditionally, development teams can integrate static analysis tools such as govulncheck into build pipelines. This automated scanning flags instances of vulnerable go-git versions within the compiled binaries before deployment.

Fix Analysis (2)

Technical Appendix

CVSS Score
7.1/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

Affected Systems

Applications using go-gitCI/CD pipelines relying on programmatic git cloningDeveloper tools using go-git integrations

Affected Versions Detail

Product
Affected Versions
Fixed Version
go-git
go-git
< 5.19.25.19.2
go-git
go-git
>= 6.0.0-alpha.1, < 6.0.0-alpha.56.0.0-alpha.5
AttributeDetail
CWE IDCWE-59
Attack VectorNetwork
CVSS Score7.1 (High)
Exploit StatusNone / Poc Conceptual
CISA KEV StatusNot Listed
Primary WeaknessImproper Link Resolution Before File Access

MITRE ATT&CK Mapping

T1204.001User Execution: Malicious Link
Execution
T1491Defacement
Impact
CWE-59
Improper Link Resolution Before File Access ('Link Following')

Improper Link Resolution Before File Access ('Link Following')

References & Sources

  • [1]GitHub Security Advisory GHSA-hc8v-wwc9-vgxm
  • [2]NVD - CVE-2026-71556

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
3 views•6 min read
•about 2 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
5 views•6 min read
•about 4 hours ago•CVE-2026-105646
4.9

CVE-2026-105646: Regular Expression Denial of Service in Ghost CMS Import Handlers

An authenticated Regular Expression Denial of Service (ReDoS) vulnerability in TryGhost Ghost (CMS) versions 4.0.0 through 6.66.x. An attacker with administrator privileges can upload crafted content import archives containing pathological directory names or migration patterns, triggering exponential backtracking in the Node.js V8 engine.

Alon Barad
Alon Barad
8 views•6 min read
•about 5 hours ago•CVE-2026-105645
4.9

CVE-2026-105645: Regular Expression Denial of Service (ReDoS) in Ghost CMS

CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.

Amit Schendel
Amit Schendel
8 views•6 min read
•about 6 hours ago•CVE-2026-105644
6.8

CVE-2026-105644: Stored Cross-Site Scripting via Malicious SVG Content Import in Ghost CMS

A Stored Cross-Site Scripting (XSS) and Unrestricted Upload of File with Dangerous Type vulnerability in Ghost CMS (versions 4.0.0 to 6.66.x) allows remote attackers to execute arbitrary JavaScript in the context of an administrator's session. The flaw lies in the content import subsystem, which extracted and stored SVG files without sanitization or binary verification.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 7 hours ago•CVE-2026-105643
7.3

CVE-2026-105643: Stored Cross-Site Scripting and Isolation Bypass in Ghost CMS

Stored Cross-Site Scripting (XSS) and origin isolation bypass vulnerability in Ghost CMS versions 6.34.0 through 6.66.1 allows low-privileged staff users to execute arbitrary JavaScript in the context of an administrator session via crafted embed cards.

Alon Barad
Alon Barad
9 views•6 min read