Git Annex is a distributed file-synchronization tool that extends Git to manage large binary files across decentralized repositories, presenting a narrow but specialized attack surface. The vendor's disclosures have centered on its core product and reflect the complexity of file handling and data integrity in a distributed version-control context. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Git Annex Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12976HIGH git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxy | Aug 20, 2017 | 8.8 | 28 | NO | NO |
CVE-2018-10857HIGH git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private | Jul 16, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-10859HIGH git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to | Jul 16, 2018 | 7.5 | 24 | NO | NO |
CVE-2014-6274HIGH git-annex had a bug in the S3 and Glacier remotes where if embedcreds=yes
was set, and the remote used encryption=pubkey or encryption=hybrid,
the embedded AWS credentials were sto | Jun 26, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Git Annex Project.
Media articles that mention a CVE ID that affects a product developed by Git Annex Project — matched by CVE ID, not by vendor name.