
🚨High - go-git Worktree Symlink Escape (CVE-2026-71556) go-git worktree ops in http://github.com/go-git/go-git may follow existing symlinks during checkout/status/add, allowing path resolution to escape the worktree. A malicious repo can read/write arbitrary host files (incl. .git/config) via crafted symlink paths. Bare repos without a worktree aren’t impacted. 👉Affected: http://github.com/go-git/go-git/v5 < 5.19.2; http://github.com/go-git/go-git/v6 < 6.0.0-alpha.5 | Upgrade to 5.19.2 / 6.0.0-alpha.5
Post summary
The advisory identifies a High‑severity worktree symlink escape in go‑git and provides specific version upgrades as the remedy.
