CVE-2025-48384

HIGH KEV

Git - Info Disclosure

Title source: llm

Description

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

Exploits (55)

nomisec WORKING POC 50 stars
by acheong08 · client-side
https://github.com/acheong08/CVE-2025-48384
nomisec WORKING POC 20 stars
by liamg · client-side
https://github.com/liamg/CVE-2025-48384
nomisec WORKING POC 1 stars
by zr0n · poc
https://github.com/zr0n/CVE-2025-48384-main
nomisec NO CODE 1 stars
by zr0n · poc
https://github.com/zr0n/CVE-2025-48384-sub
nomisec WORKING POC 1 stars
by beishanxueyuan · client-side
https://github.com/beishanxueyuan/CVE-2025-48384-test
nomisec WORKING POC 1 stars
by IK-20211125 · client-side
https://github.com/IK-20211125/CVE-2025-48384
nomisec WORKING POC 1 stars
by vinieger · poc
https://github.com/vinieger/vinieger-CVE-2025-48384-Dockerfile
nomisec NO CODE
by sathish46-lab · poc
https://github.com/sathish46-lab/CVE-2025-48384-submodule
nomisec NO CODE
by anthonyc53 · poc
https://github.com/anthonyc53/cve-2025-48384
gitlab STUB
by testdjshan · poc
https://gitlab.com/testdjshan/cve-2025-48384
gitlab WORKING POC
by burpsiteburp · poc
https://gitlab.com/burpsiteburp/CVE-2025-48384
nomisec STUB
by DayDayDayDreaming · client-side
https://github.com/DayDayDayDreaming/backup-exec-cve-48384
nomisec WORKING POC
by vignesh21-git · poc
https://github.com/vignesh21-git/CVE-2025-48384
nomisec STUB
by vignesh21-git · poc
https://github.com/vignesh21-git/CVE-2025-48384-submodule
github WORKING POC
by MarcoTondolo · client-side
https://github.com/MarcoTondolo/cve-2025-48384-poc
github NO CODE
by mukesh-610 · shellpoc
https://github.com/mukesh-610/cve-2025-48384-exploit
nomisec WRITEUP
by s41r4j · poc
https://github.com/s41r4j/CVE-2025-48384
nomisec STUB
by s41r4j · client-side
https://github.com/s41r4j/CVE-2025-48384-submodule
nomisec STUB
by butyraldehyde · client-side
https://github.com/butyraldehyde/CVE-2025-48384-PoC
nomisec NO CODE
by butyraldehyde · poc
https://github.com/butyraldehyde/CVE-2025-48384-PoC-Part2
nomisec STUB
by beishanxueyuan · poc
https://github.com/beishanxueyuan/CVE-2025-48384
github SCANNER
by EdwardYeIntrix · pythonpoc
https://github.com/EdwardYeIntrix/CVE-2025-48384-Scanner
nomisec WORKING POC
by jacobholtz · client-side
https://github.com/jacobholtz/CVE-2025-48384-poc
nomisec WORKING POC
by arun1033 · poc
https://github.com/arun1033/CVE-2025-48384
nomisec STUB
by jacobholtz · poc
https://github.com/jacobholtz/CVE-2025-48384-submodule
nomisec STUB
by eliox01 · poc
https://github.com/eliox01/CVE-2025-48384
nomisec NO CODE
by replicatorbot · client-side
https://github.com/replicatorbot/CVE-2025-48384-POC
nomisec NO CODE
by replicatorbot · poc
https://github.com/replicatorbot/CVE-2025-48384
nomisec NO CODE
by fluoworite · client-side
https://github.com/fluoworite/CVE-2025-48384
nomisec NO CODE
by fluoworite · poc
https://github.com/fluoworite/CVE-2025-48384-sub
nomisec NO CODE
by f1shh · local
https://github.com/f1shh/CVE-2025-48384
nomisec STUB
by elprogramadorgt · poc
https://github.com/elprogramadorgt/CVE-2025-48384
nomisec STUB
by Anezatraa · poc
https://github.com/Anezatraa/CVE-2025-48384-submodule
nomisec WORKING POC
by nguyentranbaotran · client-side
https://github.com/nguyentranbaotran/cve-2025-48384-poc
nomisec STUB
by admin-ping · poc
https://github.com/admin-ping/CVE-2025-48384-RCE
nomisec NO CODE
by altm4n · client-side
https://github.com/altm4n/cve-2025-48384
nomisec NO CODE
by altm4n · poc
https://github.com/altm4n/cve-2025-48384-hub
nomisec NO CODE
by ECHO6789 · poc
https://github.com/ECHO6789/CVE-2025-48384-submodule
github WORKING POC
by manus-use · postscriptpoc
https://github.com/manus-use/cve-pocs/tree/main/git-CVE-2025-48384
nomisec STUB
by testdjshan · client-side
https://github.com/testdjshan/CVE-2025-48384
nomisec NO CODE
by greatyy · client-side
https://github.com/greatyy/CVE-2025-48384-p
nomisec NO CODE
by NigelX · poc
https://github.com/NigelX/CVE-2025-48384
nomisec NO CODE
by ppd520 · client-side
https://github.com/ppd520/CVE-2025-48384
nomisec STUB
by liamg · poc
https://github.com/liamg/CVE-2025-48384-submodule
nomisec WORKING POC
by fishyyh · client-side
https://github.com/fishyyh/CVE-2025-48384-POC
nomisec NO CODE
by kallydev · poc
https://github.com/kallydev/cve-2025-48384-hook
nomisec STUB
by fishyyh · poc
https://github.com/fishyyh/CVE-2025-48384
vulncheck_xdb NO CODE
client-side
https://github.com/mukesh-610/cve-2025-48384

Scores

CVSS v3 8.0
EPSS 0.0047
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CISA KEV 2025-08-25
VulnCheck KEV 2025-08-25
ENISA EUVD EUVD-2025-20677
CWE
CWE-436 CWE-59
Status published
Products (3)
apple/xcode < 26.0
debian/debian_linux 11.0
git-scm/git < 2.43.7
Published Jul 08, 2025
KEV Added Aug 25, 2025
Tracked Since Feb 18, 2026