CVE-2024-32002 is a critical vulnerability affecting Git versions prior to 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. This flaw allows an attacker to craft a malicious Git repository with submodules that can write arbitrary files into the .git/ directory during a clone operation, enabling the execution of malicious hooks. Rated with a CVSS score of 9.0 (CRITICAL), the vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability, though it requires high attack complexity. The EPSS score of 0.803770000 indicates a high likelihood of exploitation. While not currently listed on the KEV catalog, there is public exploit intelligence, including a detailed write-up on exploiting the vulnerability, and significant community discussion, suggesting active interest and potential for in-the-wild exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.39.4CPE matchmatch criteria | cpe:2.3:a:git:git:*:*:*:*:*:*:*:* | ||
>= 2.40.0, < 2.40.2CPE matchmatch criteria | cpe:2.3:a:git:git:*:*:*:*:*:*:*:* | ||
>= 2.42.0, < 2.42.2CPE matchmatch criteria | cpe:2.3:a:git:git:*:*:*:*:*:*:*:* | ||
>= 2.43.0, < 2.43.4CPE matchmatch criteria | cpe:2.3:a:git:git:*:*:*:*:*:*:*:* | ||
2.41.0CPE matchmatch criteria | cpe:2.3:a:git:git:2.41.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.1 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk SOAR - July 2025
Jul 7, 2025GitHub: CVE-2024-32002 Recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
May 14, 2024git: Recursive clones RCE
May 14, 2024