Junglewise Threat Intelligence

CVE-2025-26625: Git LFS arbitrary file write via symbolic link traversal

CVE-2025-26625 · Severity: high · CVSS 4 · Published 2025-10-17

Technologies: github.com/git-lfs/git-lfs/v3 (Go), github.com/git-lfs/git-lfs (Go). Vendors: Go.

Executive brief

Git LFS is a tool used to manage large files in Git repositories. A vulnerability exists where specially crafted repositories containing symbolic or hard links can trick the tool into writing files to locations outside of the intended project folder. This could allow an attacker to overwrite sensitive system files or configuration data if a user clones or updates a malicious repository.

Technical details

A link-following vulnerability (CWE-59) exists in Git LFS versions 0.5.2 through 3.7.0. When executing 'git lfs checkout' or 'git lfs pull', the application fails to properly validate if path components in the working tree are symbolic links before writing LFS object contents. An attacker can craft a repository where a tracked LFS file path collides with a symbolic or hard link pointing outside the repository boundaries. This allows arbitrary file writes on the victim's filesystem when the repository is populated. The fix, introduced in version 3.7.1, implements path validation similar to core Git, ensuring each path component is a directory and removing existing files before writing new ones.

Affected products

  • Git LFS git-lfs >= 0.5.2, <= 3.7.0

Timeline

  • 2025-10-17: advisory: GHSA-6pvw-g552-53c5 published
  • 2025-10-17: patched: Version 3.7.1 released

References

Related threats