Git Large File Storage is a widely adopted extension for managing large binary files within Git repositories, despite its narrow product scope. The vulnerability profile centers on its single product and recurs through weakness classes including untrusted search-path handling, improper input validation, and uncontrolled search-path elements, reflecting the risks inherent to file-system interactions in a distributed version-control context. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Git Large File Storage Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-27955CRITICAL Git LFS 2.12.0 allows Remote Code Execution. | Nov 5, 2020 | 9.8 | 83 | NO | YES |
CVE-2017-17831HIGH GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfs | Dec 21, 2017 | 8.8 | 29 | NO | NO |
CVE-2022-24826HIGH On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `git.exe` is not found in `PATH`, the `..exe` program will be e | Apr 20, 2022 | 7.8 | 27 | NO | NO |
CVE-2021-21237HIGH Git LFS is a command line extension for managing large files with Git. On Windows, if Git LFS operates on a malicious repository with a git.bat or git.exe file in the current direc | Jan 15, 2021 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Git Large File Storage Project.
Media articles that mention a CVE ID that affects a product developed by Git Large File Storage Project — matched by CVE ID, not by vendor name.