Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-9390

76
FAUCET Score

CVE-2014-9390 is a critical vulnerability affecting Git, Mercurial, Apple Xcode, and related Git client libraries on Windows and OS X. It allows remote Git servers to execute arbitrary commands on a client system by crafting a malicious .git/config file within a repository. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA’s KEV catalog, a Metasploit module exists, and it has garnered significant community discussion and media coverage, indicating its potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.8.5.6CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 1.9.0, < 1.9.5CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.0.5CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.1.0, < 2.1.4CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.2.0, < 2.2.1CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
63.18%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: Malicious Git and Mercurial HTTP Server For CVE-2014-9390 · Dec 18, 2014
This CVE's current EPSS score of 0.6318 is in the 97th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

mavenpatch availablevia ghsa
Product: org.eclipse.jgit:org.eclipse.jgitFixed in: 3.5.3
pippatch availablevia ghsa
Product: mercurialFixed in: 3.2.3
applevendor investigatingvia nvd_reference
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

mavenGHSA-6vvc-c2m3-cjf3critical

JGit Improper Input Validation vulnerability

May 17, 2022
redhatCVE-2014-9390Low

git: arbitrary command execution vulnerability on case-insensitive file systems

Dec 18, 2014

References

article.gmane.org / gmane.linux.kernel/1853266
Broken Link
git-blame.blogspot.com / 2014/12/git-1856-195-205-214-and-221-and.html
Third Party Advisory
mercurial.selenic.com / wiki/WhatsNew
Release NotesThird Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
github.com / blog/1938-git-client-vulnerability-announced
Vendor Advisory
github.com / libgit2/libgit2/commit/928429c5c96a701bcbcafacb2421a82602b36915
Third Party Advisory
libgit2.org / security
Product
news.ycombinator.com / item
Issue TrackingPatchThird Party Advisory
support.apple.com / kb/HT204147
Vendor Advisory