Git for Windows is a distribution of the Git version-control system for the Windows platform, presenting a focused attack surface centered on a single product. The recurring weakness classes span information-disclosure issues, path-traversal flaws, and improper authentication controls, which reflect the authentication and file-access semantics inherent to a distributed version-control tool. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitforwindows over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11235HIGH In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, | May 30, 2018 | 7.8 | 53 | NO | NO |
CVE-2021-46101HIGH In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly. | Jan 31, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-31012HIGH Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git for Windows' installer execute a binary into `C:\mi | Jul 12, 2022 | 7.3 | 23 | NO | NO |
CVE-2025-66413MEDIUM Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking them into cloning from a malicious server. Since NTLM hashin | Mar 10, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitforwindows.
Media articles that mention a CVE ID that affects a product developed by Gitforwindows — matched by CVE ID, not by vendor name.