PT-2025-31443 · Gitproxy · Git-Proxy

Dgl

·

Published

2025-07-30

·

Updated

2025-07-31

·

CVE-2025-54584

CVSS v4.0
7.0
VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

Name of the Vulnerable Software and Affected Versions:

GitProxy versions 1.19.1 and below

Description:

GitProxy is an application that acts as an intermediary between developers and a Git remote endpoint. A crafted malicious Git packfile can exploit the PACK signature detection in the `parsePush.ts` file. Embedding a misleading PACK signature within commit content and carefully constructing the packet structure can trick the parser into treating invalid data as the packfile, potentially allowing bypassing approval or hiding commits.

Recommendations:

Update to version 1.19.2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54584
GHSA-XXMH-RF63-QWJV

Affected Products

Git-Proxy