CVE-2020-27955
CRITICALGit Remote Code Execution via git-lfs (CVE-2020-27955)
Title source: metasploitDescription
Git LFS 2.12.0 allows Remote Code Execution.
Exploits (20)
nomisec
WORKING POC
30 stars
by ExploitBox · poc
https://github.com/ExploitBox/git-lfs-RCE-exploit-CVE-2020-27955
nomisec
WORKING POC
15 stars
by ExploitBox · poc
https://github.com/ExploitBox/git-lfs-RCE-exploit-CVE-2020-27955-Go
metasploit
WORKING POC
EXCELLENT
by Dawid Golunski, space-r7, jheysel-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/git_lfs_rce.rb
References (7)
Scores
CVSS v3
9.8
EPSS
0.9293
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (2)
git_large_file_storage_project/git_large_file_storage
git-lfs/git-lfs
< 2.12.1Go
Timeline
Published
Nov 05, 2020
Tracked Since
Feb 18, 2026