Executive brief
gitoxide is a Rust implementation of Git used by developers and automated tools to manage source code repositories. A flaw in how gitoxide handles file checkout on Windows allows an attacker to write files outside the intended project directory by exploiting symlink handling. An attacker who controls a Git repository's contents could overwrite arbitrary files on a developer's system during repository operations.
Technical details
The vulnerability exists in gix_worktree_state::checkout() and involves improper link resolution (CWE-59). When checkout is performed with destination_is_initially_empty set to false (incremental/non-exclusive checkout) on Windows with core.symlinks enabled, the function follows an existing symlink reparse point. An attacker first checks out a symlink entry (mode 120000) at path P pointing outside the worktree, creating a reparse point. A subsequent incremental checkout replacing that path with a regular file (mode 100644) follows the existing reparse point and writes the blob content through the symlink, overwriting arbitrary files outside the worktree. The vulnerable condition requires: Windows OS, core.symlinks = true (default), destination_is_initially_empty = false (default from Repository::checkout_options()), and attacker-controlled repository content. Patches are available in gix 0.86.0, gix-worktree-state 0.33.0, gix-worktree 0.55.0, and gix-features 0.49.0.
Affected products
- Gitoxide Labs gitoxide before 0.86.0
- Gitoxide Labs gix-worktree-state before 0.33.0
- Gitoxide Labs gix-worktree before 0.55.0
- Gitoxide Labs gix-features before 0.49.0
Timeline
- 2026-08-28: disclosed: CVE-2026-82248 published
- 2026-08-02: patched: Security advisory GHSA-pmm9-4h7q-24c8 published with patches