Junglewise Threat Intelligence

CVE-2024-53263: GO-2025-3390 - Git LFS permits exfiltration of credentials via crafted HTTP URLs in github.com/git-lfs/git-lfs

CVE-2024-53263 · Severity: medium · CVSS 4 · Published 2025-01-15

Technologies: github.com/git-lfs/git-lfs/v3 (Go), github.com/git-lfs/git-lfs (Go). Vendors: Go.

Executive brief

Git LFS permits exfiltration of credentials via crafted HTTP URLs in github.com/git-lfs/git-lfs

Affected products

  • Go github.com/git-lfs/git-lfs/v3
  • Go github.com/git-lfs/git-lfs

Related threats