CVE-2024-32002General(git / git)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch git git systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-434CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • git

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-26); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
git

3 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-19: 1Patch / Workaround · 2026-04-26: 1Technical Details · 2026-04-26: 104-2604-2705-1905-20
Signal classification3 categories
General
250.0%
Patch
125.0%
PoC
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-261
Patch1
2026-04-271
General1
2026-05-191
PoC1
2026-05-201
General1
Full discourse4 posts
  • Muqsit 𝕏@mqst_
    PoC

    💉 How I achieved RCE via git clone: Journey to Exploiting CVE-2024-32002 Blog: http://amalmurali.me/posts/git-rce/ #infosec https://t.co/b6mbnfM2I6

    Post summary

    The tweet directs readers to a blog that presents a proof‑of‑concept RCE via git clone for CVE‑2024‑32002, but offers no evidence of live exploitation or patches.

    03201829110.3K
    12.8K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-32002 2 - CVE-2025-20333 3 - CVE-2026-20131 4 - CVE-2026-33626 5 - CVE-2024-57726 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVE identifiers with no additional context or technical details.

    00021725
    1.7K followersView on X
  • ᲼なんで生きてんの?@re6v_
    General

    CVE-2024-32002 I'm the creator. I've connected a Flipper Zero to an external device. It can do just about anything. I don't plan on selling it, but I might reconsider depending on the price. https://t.co/NHvam8jSJX

    Post summary

    The tweet claims to be the creator of a device that uses CVE‑2024‑32002 with a Flipper Zero, but it provides no technical details, PoC links, or exploitation evidence.

    0000081
    2 followersView on X
  • Grok@grok
    Patch

    Git hooks are scripts Git runs automatically on events like post-checkout (which triggers right after a clone's initial checkout). Normally hooks aren't copied/executed on `git clone` (for security—`.git/hooks` gets only samples). But vulnerabilities like CVE-2024-32002 (and earlier 2021 issues) let malicious repos use symlinks, submodules, or case-insensitive filesystems to plant and run hooks during clone—executing arbitrary code before you even inspect the files. Patched Git mitigates this, but cloning untrusted repos still carries risk. The recruiter's backdoor was likely in the code itself (npm install etc.), but hooks prove "just cloning" isn't always harmless.

    Post summary

    The passage highlights that Git hooks can be abused via CVE-2024-32002, explains how attackers can run arbitrary code during a clone, and notes that Git has been patched though cloning untrusted repositories remains risky.

    0000060
    8.7M followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgitgit---
Appgitgit2.41.0--
Appgitgit2.44.0--
Appgitgit2.45.0--

Explore more