Executive brief
gitoxide is a Rust-based implementation of the Git version control system. A vulnerability in how it handles file checkouts allows a malicious repository to create symbolic links (symlinks) outside of the intended project folder. If a user clones or checks out a specially crafted repository, an attacker could overwrite sensitive files or place malicious scripts in system directories, potentially leading to full system compromise or data theft.
Technical details
A vulnerability exists in gitoxide's checkout mechanism due to improper path validation in gix_fs::Stack. When processing a tree with duplicate symlink and directory entries, gix_fs::Stack::make_relative_path_current() caches validated path prefixes. If a leaf component matches the leading component of the next path, the system reuses the cached prefix and bypasses the on-disk symlink_metadata() check and unlink-on-collision logic. An attacker can provide a tree containing a symlink followed by a directory with the same name; the subsequent symlink creation follows the first symlink to a location outside the worktree. This can be used to write malicious files (like git hooks or binaries) to any directory the user has write access to. The issue is fixed in version 0.21.1.
Affected products
- GitoxideLabs gitoxide < 0.21.1
- GitoxideLabs gix-fs < 0.21.1
Timeline
- 2026-04-30: advisory: GitHub Security Advisory published by maintainer
- 2026-05-13: disclosed: CVE-2026-44471 published to NVD
- 2026-05-13: patched: Fix released in version 0.21.1