Executive brief
Git LFS permits exfiltration of credentials via crafted HTTP URLs in github.com/git-lfs/git-lfs
Affected products
- Go github.com/git-lfs/git-lfs/v3
- Go github.com/git-lfs/git-lfs
Junglewise Threat Intelligence
CVE-2024-53263 · Severity: medium · CVSS 4 · Published 2025-01-15
Technologies: github.com/git-lfs/git-lfs/v3 (Go), github.com/git-lfs/git-lfs (Go). Vendors: Go.
Git LFS permits exfiltration of credentials via crafted HTTP URLs in github.com/git-lfs/git-lfs