Junglewise Threat Intelligence

CVE-2025-54585: FINOS GitProxy authorization bypass in new branch creation

CVE-2025-54585 · Severity: medium · CVSS 4 · Published 2025-07-30

Technologies: @finos/git-proxy (npm). Vendors: npm.

Executive brief

GitProxy is a security tool that sits between developers and a Git server to enforce code approval policies. A vulnerability was found where an attacker could bypass these mandatory approval checks by creating a new branch from an unapproved commit and getting a subsequent minor change approved on that new branch. This allows unauthorized code to be pushed to protected repositories, potentially compromising the integrity of the software development lifecycle.

Technical details

A vulnerability in GitProxy versions 1.19.1 and earlier allows for an authorization bypass (CWE-285) during the push process. The application uses a null hash (00000000...) to detect new branch creation in 'getDiff.ts' and 'parsePush.ts'. An attacker with standard push access can commit unapproved code to a parent branch, create a new child branch from that commit, and obtain approval for a secondary commit on the child branch. Due to flawed logic in how the proxy tracks pending approvals across branches, pushing the child branch can inadvertently validate and allow the original unapproved parent commits to reach the remote repository. This is fixed in version 1.19.2 by requiring explicit approval for commits originating from the parent branch during such flows.

Affected products

  • FINOS @finos/git-proxy <= 1.19.1

Timeline

  • 2025-07-30: disclosed
  • 2025-07-30: advisory
  • 2025-07-30: patched: Fixed in version 1.19.2

References

Related threats