PT-2025-31443 · Gitproxy · Git-Proxy
Dgl
·
Published
2025-07-30
·
Updated
2025-07-31
·
CVE-2025-54584
CVSS v4.0
7.0
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
GitProxy versions 1.19.1 and below
Description
GitProxy is an application that acts as an intermediary between developers and a Git remote endpoint. A crafted malicious Git packfile can exploit the PACK signature detection in the
parsePush.ts file. Embedding a misleading PACK signature within commit content and carefully constructing the packet structure can trick the parser into treating invalid data as the packfile, potentially allowing bypassing approval or hiding commits.Recommendations
Update to version 1.19.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Git-Proxy