CVE-2021-21237 is a critical vulnerability in Git LFS on Windows, allowing arbitrary code execution if a user operates on a malicious repository containing a specially crafted git.bat or git.exe file in the current directory. This issue, stemming from an incomplete fix for a previous CVE, affects Git Large File Storage Project versions prior to 2.13.2. With a CVSS score of 7.8 (HIGH), it presents a significant risk due to its low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, the vulnerability's nature makes it a serious concern for Windows users of Git LFS.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.13.2CPE matchmatch criteria | cpe:2.3:a:git_large_file_storage_project:git_large_file_storage:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.