Junglewise Threat Intelligence

CVE-2025-21613: GO-2025-3368 - Argument Injection via the URL field in github.com/go-git/go-git

CVE-2025-21613 · Severity: low · CVSS 3.1 · Published 2025-01-07

Technologies: github.com/go-git/go-git/v5 (Go), gopkg.in/src-d/go-git.v4 (Go), github.com/go-git/go-git/v4 (Go). Vendors: Go.

Executive brief

Argument Injection via the URL field in github.com/go-git/go-git

Affected products

  • Go github.com/go-git/go-git/v5
  • Go gopkg.in/src-d/go-git.v4
  • Go github.com/go-git/go-git/v4

Related threats