Executive brief
gitoxide is a Git implementation library used by applications and developers to interact with Git repositories. The vulnerability allows an attacker to inject forged credential requests by embedding carriage return characters in URLs, potentially causing credential helpers to return passwords and authentication tokens for trusted hosts instead of the attacker's target. This could expose sensitive credentials if the victim application logs or returns credentials from the attacked workflow.
Technical details
The vulnerability is an improper input validation issue (CWE-116) in gitoxide's credential helper protocol serialization. The Context::write_to() function in gix-credentials validates URL values to reject NUL (0x00) and LF (0x0A) characters but fails to reject CR (0x0D), allowing bare carriage returns to pass through unchecked. When serialized to the helper line protocol, an attacker-controlled URL such as `https://evil.example\rhost=trusted.example\rprotocol=https` can be parsed by CR-sensitive credential helpers as multiple fields, causing them to return credentials for the injected trusted host instead of the attacker's domain. Exploitation requires an unauthenticated network attacker to supply a malicious URL to a gitoxide caller and depends on a credential helper that treats CR as a line terminator; helpers that split only on LF are not affected. The patch adds CR validation alongside NUL and LF checks in the validation function.
Affected products
- GitoxideLabs gitoxide before 0.38.2
Timeline
- 2026-07-15: disclosed
- 2026-08-28: patched: Version 0.38.2 released with fix