CVE-2026-44471Disclosure(gitoxidelabs / gix-fs)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitoxidelabs gix-fs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to. During checkout, all symlink index entries are deferred and created after regular files using a single shared gix_worktree::Stack. Internally, this uses a gix_fs::Stack. gix_fs::Stack::make_relative_path_current() caches validated path prefixes: when the previously-processed leaf component exactly matches the leading component(s) of the next path, the leaf-to-directory transition at gix-fs/src/stack.rs invokes only delegate.push_directory(), never delegate.push(). In gix_worktree::stack::delegate::StackDelegate, when the state member is State::CreateDirectoryAndAttributesStack, Attributes::push_directory() only loads attributes (from the ODB, in the clone case), and does not perform any other checks. The on-disk symlink_metadata() check and unlink-on-collision live in StackDelegate::push()'s invocation of create_leading_directory(), which is therefore bypassed for the cached prefix. The final symlink is created with plain std::os::unix::fs::symlink, which follows symlinks in parent directories. Therefore, it's possible to provide a tree with duplicate symlink and directory entries that exploits this. This vulnerability is fixed in 0.21.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gix-fs

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
gix-fs

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-28: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-28: 105-1305-1405-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 gitoxide, Symlink Path Traversal, #CVE-2026-44471 (Critical) -DC-May2026-14 https://dailycve.com/gitoxide-symlink-path-traversal-cve-2026-44471-critical-dc-may2026-14/

    Post summary

    The post announces CVE‑2026‑44471 as a critical symlink path traversal vulnerability in gitoxide, providing only basic classification details without any PoC, exploit, or patch information.

    0000038
    207 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44471 Symlink Creation Vulnerability in Gitoxide Prior to Version 0.21.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44471

    Post summary

    The post announces CVE-2026-44471 as a symlink creation vulnerability affecting Gitoxide versions before 0.21.1, providing a link to a vulnerability database but no proof‑of‑concept, exploit details, patch, or evidence of active exploitation.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44471 gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing a… https://www.cve.org/CVERecord?id=CVE-2026-44471

    Post summary

    CVE-2026-44471 exposes gitoxide to arbitrary write via a malicious tree; upgrading to version 0.21.1 mitigates the vulnerability.

    0000087
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitoxidelabsgix-fs-rust-

Explore more