Lucene search

K
osvGoogleOSV:GO-2021-0098
HistoryApr 14, 2021 - 8:04 p.m.

Arbitrary code execution on Windows in github.com/git-lfs/git-lfs

2021-04-1420:04:52
Google
osv.dev
17
git repository
windows
code execution
security vulnerability

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

20.4%

Due to the standard library behavior of exec.LookPath on Windows a number of methods may result in arbitrary code execution when cloning or operating on untrusted Git repositories.

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

20.4%