gix-validate
An idiomatic, lean, fast & safe pure Rust implementation of Git
Activity
- Latest release
- 3w ago
- Total releases
- 25
- Cadence
- ~44 days
- Last 12 months
- 6
Reach
- Stars
- 11.9k
Details
- License
- MIT OR Apache-2.0
- First release
- Feb 17, 2023
| Version | Released | |
|---|---|---|
0.11.4
patch
| ||
0.11.3
unknown
| ||
0.11.2
unknown
| ||
0.11.1
unknown
| ||
0.11.0
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.1
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.5
unknown
yanked
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.4
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.3
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.2
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.1
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.0
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.5
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.4
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.3
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.2
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.1
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.8.0
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.7
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.6
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.5
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.4
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.3
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
0.7.2
unknown
1 CVE
CVE-2026-82253
GHSA-p3hw-mv63-rf9w
May 05, 2026
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
High
Network
Low
None
SummarySubmodule name validation bypass plus missing validation in production code paths allows path traversal via crafted DetailsBug 1: Validation bypass in The
Bypass: Bug 2: Validation never called in production
Bug 3: Trust inheritance bypass in At
The parent's
Since trust is already PoCCompiled and executed in Rust 1.94.1
Attack chain
ImpactA crafted The trust inheritance is the critical amplifier: without it, the traversed path would undergo ownership checks that could block the attack. With it, any git directory reachable via Honest limitations
Suggested fix
SeverityHigh. Network vector (via clone), requires user interaction (submodule operations). The trust bypass enables credential disclosure from traversed git directories. Confidentiality impact is high. Fixed in
0.11.1
References Updated Sep 10, 2026 · Source: OSV.dev |