
1// The CVEs weren't exotic. They were the basics. CVE-2025-68143: git_init created repos at arbitrary filesystem paths. No boundary validation. CVE-2025-68144: Argument injection — user-controlled strings passed directly into shell commands. CVE-2025-68145: Path traversal through a parameter that was never sanitised. All three exploitable via prompt injection. All three in the reference implementation developers are told to copy.
Post summary
The text discloses three CVEs with basic technical details, noting they are exploitable via prompt injection, but provides no PoC, patch, or evidence of active exploitation.



