PT-2026-43251 · Gitoxide+2 · Gitoxide+2

CVE-2026-40034

·

Published

2026-05-05

·

Updated

2026-06-30

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions gix-submodule versions prior to 0.29.0 gitoxide versions prior to 0.5.21 gix versions prior to 0.84.0
Description Incorrect validation of the update field in .gitmodules allows attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule is initialized with only partial configuration in .git/config. This enables remote code execution by injecting arbitrary shell commands via the update field, which are executed when the Submodule::update() function is called on a previously initialized submodule.
Recommendations Update gix-submodule to version 0.29.0 or later. Update gitoxide to version 0.5.21 or later. Update gix to version 0.84.0 or later.

Exploit

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40034
GHSA-F26G-JM89-4G65
GHSA-M4F9-C775-WG56
OPENSUSE-SU-2026:11038-1
OPENSUSE-SU-2026:21185-1

Affected Products

Gitoxide
Gix
Gix-Submodule