CISA KEV · catalog date Aug 25, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2025-48384
Git allows arbitrary code execution through broken config quoting
Exploited in the wild (CISA KEV since Aug 25, 2025). security-advisories@github.com reports CVSS 3.1 8.0. EPSS estimates 4.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
- State
- PUBLISHED
- Published
- Jul 8, 2025
- Updated
- Feb 26, 2026
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAGitHub_MOriginal evidence ↗
Record text: Git allows arbitrary code execution through broken config quoting
Inspect raw assertion
- Field
container- Value
- Git allows arbitrary code execution through broken config quoting
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Git Link Following Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Git Link Following Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 4.11% probability · 90.02th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.041090000000; percentile 0.900190000000
FIRST EPSS · score date Aug 27, 2026 · 90th percentile · first observed Aug 27, 2026
security-advisories@github.com · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Git allows arbitrary code execution through broken config quoting
Inspect raw assertion
- Field
container- Value
- Git allows arbitrary code execution through broken config quoting
Git Link Following Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Git Link Following Vulnerability
4.11% probability · 90.02th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.041090000000; percentile 0.900190000000
Applicability
Cited product scope
Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
4 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "< 2.43.7"}, {"status": "affected", "version": ">= 2.44.0-rc0, < 2.44.4"}, {"status": "affected", "version": ">= 2.45.0-rc0, < 2.45.4"}, {"status": "affected", "version": ">= 2.46.0-rc0, < 2.46.4"}, {"status": "affected", "version": ">= 2.47.0-rc0, < 2.47.3"}, {"status": "affected", "version": ">= 2.48.0-rc0, < 2.48.2"}, {"status": "affected", "version": ">= 2.49.0-rc0, < 2.49.1"}, {"status": "affected", "version": ">= 2.50.0-rc0, < 2.50.1"}]product-b1ba56e48fb18ebd9e6473b135befea0c97422907c218dc623981b389d3fe99cLinked exactInspect raw assertion
cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 26.0
- Match ID
37cc7f40-cc3a-4aeb-9260-b621fe64735a
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa6feec2-9f11-4643-8827-749718254fed
product-407759b0bed8e9f6c819d88b6ca09f983ec62b54513f8e94a63045a425ebe9b2Linked exactInspect raw assertions
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 2.46.0; through excluding 2.46.4
- Match ID
01bda55c-f398-4286-abc6-979a783bdc65
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 2.44.0; through excluding 2.44.4
- Match ID
856a8970-74e2-4f8f-a1a6-2ab1c0c87e45
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 2.43.7
- Match ID
bb276680-d286-4df6-bcb7-cac1d9d77e08
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 2.50.0; through excluding 2.50.1
- Match ID
18f948ad-22c0-4b2e-b497-899f3a94b70a
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 2.47.0; through excluding 2.47.3
- Match ID
ff4a2acc-0996-4869-884d-734d6006c032
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 2.48.0; through excluding 2.48.2
- Match ID
0dd21a83-8d62-4ee4-914b-b5aca19a84a2
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 2.49.0; through excluding 2.49.1
- Match ID
95c1825c-b7a2-46e9-93d7-2d196db2515e
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 2.45.0; through excluding 2.45.4
- Match ID
6d1db9ba-3d91-4f7d-931e-a664737129f0
Affected-product evidence
Accepted scope and product mapping
3 canonical links · 1 source-reported links
vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
39df5ba2-c8d3-4c5b-bf94-cbc4dcad6735vendor-0b6b1b3171ac447bb8a39616f3f8a44f44322e5e4e0f713549281117cf0682ea · product-407759b0bed8e9f6c819d88b6ca09f983ec62b54513f8e94a63045a425ebe9b2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2064cd8d-62de-463a-847d-6a55cf42a9ca26976ad1-7bc6-4158-9f68-10506f696f4250468601-c0be-4bca-ab53-7ec99988bd6a7babcdae-e572-4ad5-b066-8010244650b480f6d8fd-06b5-47c6-b38c-05845a99defe86536bda-c317-42e9-ae15-9739a08d86bb9a9519d3-f202-4665-92bc-13d247dff723e9745d17-e2b8-4cbc-8599-db9b13469f17vendor-d6ed6f1e35de2e16a8a10f2ae364dab009bb2afadd609071b20da24d60ce2829 · product-b1ba56e48fb18ebd9e6473b135befea0c97422907c218dc623981b389d3fe99c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ebc4113e-02df-420d-89c9-b0c286a88351Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
abfa30d1-dc40-4bc1-8f30-16bf704ce1ddAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:HDirect CVE/CNA normalized decisions
GitHub_M
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H- Validation
- Base mismatch
- Recomputed
- 8.0
- Decision reason
- Outside current scoring policy
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.