Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-23946

19
FAUCET Score

CVE-2023-23946 is a path traversal vulnerability in Git, affecting versions prior to 2.39.2 and various earlier maintenance releases. A crafted input to git apply can overwrite files outside the working tree, executing as the user running the command. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on integrity. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness among threat actors.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.30.8CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.31.0, < 2.31.7CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.32.0, < 2.32.6CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.33.0, < 2.33.7CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
>= 2.34.0, < 2.34.7CPE matchmatch criteria
cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.2MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.5
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.14%
Probability of exploitation in next 30 days
EPSS Percentile
63.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0114 is in the 42nd percentile among its peer group of 51,551 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.5Fixed in: 17.5.2
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Fixed in: 16.11.25
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.0Fixed in: 17.0.20
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.4Fixed in: 17.4.6
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Fixed in: 15.9.53
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.2Fixed in: 17.2.14
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: git-0:2.31.8-1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: git-0:2.39.3-1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: git-0:2.39.3-1.el8_8
View patch

Vendor Advisories (2)

microsoft2023-Mar/CVE-2023-23946Important

GitHub: CVE-2023-23946 mingit Remote Code Execution Vulnerability

Mar 14, 2023
redhatCVE-2023-23946Moderate

git: git apply: a path outside the working tree can be overwritten with crafted input

Feb 14, 2023

References

github.com / git/git/commit/c867e4fa180bec4750e9b54eb10f459030dbebfd
Patch
github.com / git/git/security/advisories/GHSA-r87m-v37r-cwfh
Vendor Advisory
security.gentoo.org / glsa/202312-15