Security: git-for-windows/git
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on WindowsGHSA-xrpg-8j9v-v282 published
Aug 11, 2026 by dschoHigh -
Two remaining one-WCHAR heap corruptions in git-credential-wincred store/erase pathsGHSA-rxqw-wxqg-g7hw published
Jul 14, 2026 by dschoModerate -
`git clone` from manipulated repositories can leak NTLM hashes to arbitrary serversGHSA-9j5h-h4m7-85hx published
Apr 15, 2026 by dschoHigh -
Git leaks NTLM hash when cloning from an attacker-controlled serverGHSA-hv9c-4jm9-jh3x published
Mar 10, 2026 by dschoHigh -
Git CMD erroneously executes `doskey.exe` in the current directory, if it existsGHSA-gq5x-v87v-8f7g published
Apr 25, 2023 by vdyeHigh -
The config file of `connect.exe` is susceptible to malicious placingGHSA-g4fv-xjqw-q7jm published
Apr 25, 2023 by vdyeHigh -
Git looks for localized messages in an unprivileged placeGHSA-9w66-8mq8-5vm8 published
Apr 25, 2023 by vdyeLow -
gitk can inadvertently call executables in the worktreeGHSA-wxwv-49qw-35pm published
Feb 14, 2023 by derrickstoleeHigh -
Git for Windows' installer is susceptible to DLL side loading attacksGHSA-p2x9-prp4-8gvq published
Feb 14, 2023 by derrickstoleeHigh -
Git GUI Clone Remote Code Execution VulnerabilityGHSA-v4px-mx59-w99c published
Jan 17, 2023 by derrickstoleeHigh