Vulnerability Report: GO-2025-3390
- CVE-2024-53263, GHSA-q6r2-x2cc-vrp7
- Affects: github.com/git-lfs/git-lfs, github.com/git-lfs/git-lfs/v3
- Published: Jan 15, 2025
Git LFS permits exfiltration of credentials via crafted HTTP URLs in github.com/git-lfs/git-lfs
For detailed information about this vulnerability, visit https://github.com/git-lfs/git-lfs/security/advisories/GHSA-q6r2-x2cc-vrp7.
Affected Modules
-
PathGo Versions
-
all versions, no known fixed
-
from v3.0.0 before v3.6.1
Aliases
References
- https://github.com/git-lfs/git-lfs/security/advisories/GHSA-q6r2-x2cc-vrp7
- https://github.com/git-lfs/git-lfs/commit/0345b6f816e611d050c0df67b61f0022916a1c90
- https://github.com/git-lfs/git-lfs/releases/tag/v3.6.1
- https://vuln.go.dev/ID/GO-2025-3390.json
Credits
- @Ry0taK
Feedback
See anything missing or incorrect?
Suggest an edit to this report.