Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-48384

66
FAUCET Score

CVE-2025-48384 is a critical vulnerability in Git that affects various products including Apple, Debian, and Git SCM distributions. It arises from Git's handling of trailing carriage returns in configuration values, which can lead to submodules being checked out to incorrect locations. If a symlink exists pointing the altered path to the submodule hooks directory and the submodule contains an executable post-checkout hook, this can result in unintentional execution of arbitrary code. The vulnerability has a CVSS score of 8.0 (HIGH), indicating a severe risk. It requires low privileges (PR:L) and user interaction (UI:R) but has high attack complexity (AC:H) and can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). The attack vector is network-based (AV:N), allowing remote exploitation. CVE-2025-48384 is actively exploited in the wild, as indicated by its presence in CISA's KEV catalog. While no public exploit code is available on Metasploit, Nuclei, or ExploitDB, there is significant community discussion and media coverage surrounding this vulnerability, highlighting its active exploitation and the urgency for patching.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.43.7CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.44.0, < 2.44.4CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.45.0, < 2.45.4CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.46.0, < 2.46.4CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.47.0, < 2.47.3CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.77%
Probability of exploitation in next 30 days
EPSS Percentile
84.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Aug 25, 2025
This CVE's current EPSS score of 0.0278 is in the 93rd percentile among its peer group of 102 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (42)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Fixed in: 15.9.75
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.8Fixed in: 17.8.23
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.10Fixed in: 17.10.17
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.12Fixed in: 17.12.10
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.14Fixed in: 17.14.8
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Fixed in: 16.11.49
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: git-0:2.27.0-5.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: git-0:2.31.8-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: git-0:2.31.8-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: git-0:2.31.8-3.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: git-0:2.39.5-1.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: git-0:2.39.5-1.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: git-0:2.47.3-1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: git-0:2.31.1-6.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: git-0:2.39.5-1.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: git-0:2.43.5-1.el9_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: rhcos-412.86.202509030110-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202509030117-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: rhcos-414.92.202508270040-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202508192014-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202508261955-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202508141510-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202508060022-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: rhcos-4.19.9.6.202508112354-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.11 on RHEL 9Fixed in: web-terminal/web-terminal-rhel9-operator:1.11-19
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.11 on RHEL 9Fixed in: web-terminal/web-terminal-tooling-rhel9:1.11-8
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-businesscentral-monitoring-rhel8:7.13.5-4.1753280805
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-businesscentral-rhel8:7.13.5-4.1753280812
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-controller-rhel8:7.13.5-4.1752676933
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-dashbuilder-rhel8:7.13.5-3.1752676926
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-kieserver-rhel8:7.13.5-4.1752676932
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-operator-bundle:7.13.5-27
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-process-migration-rhel8:7.13.5-4.1752676925
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-rhel8-operator:7.13.5-2.1752676931
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rhpam-7/rhpam-smartrouter-rhel8:7.13.5-4.1752676930
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Terminal 1.12 on RHEL 9Fixed in: web-terminal/web-terminal-tooling-rhel9:1.12-4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: git-0:2.47.3-1.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: git-0:1.8.3.1-25.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: git-0:2.43.7-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: git-0:2.18.4-5.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: git-0:2.27.0-5.el8_4.1
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

redhatCVE-2025-48384Important

git: Git arbitrary code execution

Jul 8, 2025
microsoft2025-Jul/CVE-2025-48384

GitHub: CVE-2025-48384 Git Symlink Vulnerability

Jul 8, 2025

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
seclists.org / fulldisclosure/2025/Sep/60
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00003.html
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2025/07/08/4
Mailing List
github.com / git/git/security/advisories/GHSA-vwqx-4fm8-6qc9
Vendor Advisory