CVE-2025-48384
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.
- CVSS v3.1
- 8.0 HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H - EPSS
- 4.11% chance of exploitation in the next 30 days, 90th percentile
- CISA KEV
- added 2025-08-25
- Published
- 2025-07-08
- Updated
- 2026-02-26
Proof-of-concept exploits (37)
- Anezatraa/CVE-2025-48384-submodule0★ · 2025-07-19
- ECHO6789/CVE-2025-48384-submodule0★ · 2025-07-15
- IK-20211125/CVE-2025-483841★ · 2025-07-21
- NigelX/CVE-2025-483840★ · 2025-07-10
- acheong08/CVE-2025-4838453★ · 2025-07-08
- admin-ping/CVE-2025-48384-RCE0★ · 2025-07-17
- altm4n/cve-2025-483840★ · 2025-07-16
- arun1033/CVE-2025-483840★ · 2025-08-29
- beishanxueyuan/CVE-2025-483840★ · 2025-09-10
- beishanxueyuan/CVE-2025-48384-test1★ · 2025-08-04
- butyraldehyde/CVE-2025-48384-PoC0★ · 2025-09-23
- butyraldehyde/CVE-2025-48384-PoC-Part20★ · 2025-09-23
- eliox01/CVE-2025-483840★ · 2025-08-25
- elprogramadorgt/CVE-2025-483840★ · 2025-07-25
- f1shh/CVE-2025-483840★ · 2025-08-01
- fishyyh/CVE-2025-483840★ · 2025-07-09
- fishyyh/CVE-2025-48384-POC0★ · 2025-07-09
- fluoworite/CVE-2025-483840★ · 2025-08-03
- fluoworite/CVE-2025-48384-sub0★ · 2025-08-03
- greatyy/CVE-2025-48384-p0★ · 2025-07-10
- jacobholtz/CVE-2025-48384-poc0★ · 2025-09-02
- jacobholtz/CVE-2025-48384-submodule0★ · 2025-08-28
- kallydev/cve-2025-48384-hook0★ · 2025-07-09
- liamg/CVE-2025-4838420★ · 2025-07-09
- liamg/CVE-2025-48384-submodule0★ · 2025-07-09
- nguyentranbaotran/cve-2025-48384-poc0★ · 2025-07-17
- ppd520/CVE-2025-483840★ · 2025-07-09
- replicatorbot/CVE-2025-483840★ · 2025-08-20
- replicatorbot/CVE-2025-48384-POC0★ · 2025-08-20
- s41r4j/CVE-2025-483840★ · 2025-10-02
- s41r4j/CVE-2025-48384-submodule0★ · 2025-10-02
- testdjshan/CVE-2025-483840★ · 2025-07-10
- testtianmaaaa/CVE-2025-483840★ · 2026-06-10
- vinieger/vinieger-CVE-2025-48384-Dockerfile1★ · 2025-07-11
- MarcoTondolo/cve-2025-48384-poc
- vignesh21-git/CVE-2025-48384
- zr0n/CVE-2025-48384-main