Junglewise Threat Intelligence

CVE-2022-24826: Git LFS can execute a binary from the current directory on Windows

CVE-2022-24826 · Severity: low · CVSS 3.1 · Published 2022-04-22

Technologies: github.com/git-lfs/git-lfs/v3 (Go), github.com/git-lfs/git-lfs (Go). Vendors: Go.

Executive brief

Git LFS can execute a binary from the current directory on Windows

Affected products

  • Go github.com/git-lfs/git-lfs/v3
  • Go github.com/git-lfs/git-lfs

Related threats