CVE Explorer
CVE-2026-45571
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"go-git","vendor":"go-git","versions":[{"status":"affected","version":"< 5.19.1"},{"status":"affected","version":">= 6.0.0-alpha.1, < 6.0.0-alpha.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:58ee69afb060cf621b9cd10554857baf6226f948368026975d6ea59fbbc265f0 · sha256:29046c6ed5cf09e2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:58ee69afb060cf621b9cd10554857baf6226f948368026975d6ea59fbbc265f0 · sha256:29046c6ed5cf09e2… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:58ee69afb060cf621b9cd10554857baf6226f948368026975d6ea59fbbc265f0 · sha256:29046c6ed5cf09e2… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96","tags":["x_refsource_CONFIRM"],"url":"https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:58ee69afb060cf621b9cd10554857baf6226f948368026975d6ea59fbbc265f0 · sha256:29046c6ed5cf09e2… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.