CVE-2024-53263 is a high-severity vulnerability in Git LFS, an extension for versioning large files with Git. It allows an attacker to steal a user's Git credentials by injecting URL-encoded control characters into a remote host's URL, which Git LFS then passes to the git-credential command without proper validation. This vulnerability has a CVSS score of 8.5 (HIGH), indicating a low attack complexity and high impact on confidentiality and integrity, as it can lead to unauthorized access to repositories. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, suggesting a high potential for future exploitation. All users are advised to upgrade to Git LFS v3.6.1 immediately, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Git-Lfs | Git-Lfs | >= 0.1.0, < 3.6.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Git LFS permits exfiltration of credentials via crafted HTTP URLs
Jan 14, 2025git-lfs: Git LFS permits exfiltration of credentials via crafted HTTP URLs
Jan 14, 2025Git LFS permits exfiltration of credentials via crafted HTTP URLs
Jan 14, 2025