CVE-2020-27955

CRITICAL

Git Remote Code Execution via git-lfs (CVE-2020-27955)

Title source: metasploit

Description

Git LFS 2.12.0 allows Remote Code Execution.

Exploits (20)

nomisec WORKING POC 30 stars
by ExploitBox · poc
https://github.com/ExploitBox/git-lfs-RCE-exploit-CVE-2020-27955
nomisec WRITEUP 17 stars
by r00t4dm · poc
https://github.com/r00t4dm/CVE-2020-27955
nomisec WORKING POC 15 stars
by ExploitBox · poc
https://github.com/ExploitBox/git-lfs-RCE-exploit-CVE-2020-27955-Go
nomisec WORKING POC 1 stars
by TheTh1nk3r · poc
https://github.com/TheTh1nk3r/cve-2020-27955
nomisec WORKING POC 1 stars
by DeeLMind · poc
https://github.com/DeeLMind/CVE-2020-27955-LFS
nomisec STUB
by the-chivalrousZ · poc
https://github.com/the-chivalrousZ/cve-2020-27955
nomisec WRITEUP
by Marsable · poc
https://github.com/Marsable/CVE-2020-27955-LFS
nomisec WORKING POC
by Kimorea · poc
https://github.com/Kimorea/CVE-2020-27955-LFS
nomisec WORKING POC
by z50913 · poc
https://github.com/z50913/CVE-2020-27955
nomisec WORKING POC
by HK69s · poc
https://github.com/HK69s/CVE-2020-27955
nomisec STUB
by nob0dy-3389 · poc
https://github.com/nob0dy-3389/CVE-2020-27955
nomisec NO CODE
by NeoDarwin · poc
https://github.com/NeoDarwin/CVE-2020-27955
nomisec NO CODE
by IanSmith123 · poc
https://github.com/IanSmith123/CVE-2020-27955
nomisec WORKING POC
by Arnoldqqq · poc
https://github.com/Arnoldqqq/CVE-2020-27955
nomisec WORKING POC
by whitetea2424 · poc
https://github.com/whitetea2424/CVE-2020-27955-LFS-main
nomisec NO CODE
by FrostsaberX · poc
https://github.com/FrostsaberX/CVE-2020-27955
nomisec STUB
by userxfan · poc
https://github.com/userxfan/cve-2020-27955
nomisec NO CODE
by yhsung · poc
https://github.com/yhsung/cve-2020-27955-poc
metasploit WORKING POC EXCELLENT
by Dawid Golunski, space-r7, jheysel-r7 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/git_lfs_rce.rb

Scores

CVSS v3 9.8
EPSS 0.9293
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (2)

git_large_file_storage_project/git_large_file_storage
git-lfs/git-lfs < 2.12.1Go

Timeline

Published Nov 05, 2020
Tracked Since Feb 18, 2026