PT-2025-2951 · Github+9 · Git Lfs+9

Ry0Tak

·

Published

2025-01-14

·

Updated

2026-01-26

·

CVE-2024-53263

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Git LFS versions prior to 3.6.1
Description Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the git-credential(1) command without checking for embedded line-ending control characters, such as line feed (LF) or carriage return (CR), and then sends any credentials it receives back from the Git credential helper to the remote host. By inserting URL-encoded control characters into the URL, an attacker may be able to retrieve a user's Git credentials.
Recommendations Git LFS versions prior to 3.6.1 should be updated to version 3.6.1 to resolve the issue.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:0673
ALSA-2025:0845
ALSA-2025_0673
ALSA-2025_0845
ALT-PU-2025-10256
AZL-55644
AZL-55670
BDU:2025-01510
BIT-GIT-LFS-2024-53263
CESA-2025_0845
CVE-2024-53263
DLA-4028-1
DSA-5849-1
GHSA-Q6R2-X2CC-VRP7
GO-2025-3390
INFSA-2025_0673
INFSA-2025_0845
MGASA-2025-0028
OPENSUSE-SU-2025:0153-1
OPENSUSE-SU-2025:14649-1
OPENSUSE-SU-2025:14653-1
OPENSUSE-SU-2025_0297-1
RHSA-2025:0673
RHSA-2025:0757
RHSA-2025:0758
RHSA-2025:0759
RHSA-2025:0762
RHSA-2025:0765
RHSA-2025:0825
RHSA-2025:0845
RHSA-2025_0673
RHSA-2025_0845
RLSA-2025:0673
RLSA-2025:0845
SUSE-SU-2025:0297-1
USN-7977-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Git Lfs
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu