CVE-2026-71557: Path Traversal and Configuration Overwrite in go-git Filesystem Storage Engine
Vulnerability ID: CVE-2026-71557
CVSS Score: 6.3
Published: 2026-08-07
CVE-2026-71557 is a path traversal vulnerability in go-git, a pure-Go implementation of Git. In vulnerable versions, the filesystem-backed storage engine fails to validate reference names before mapping them to on-disk paths. An attacker hosting a malicious Git server can advertise references containing directory traversal sequences, such as 'refs/heads/../../config', to write or overwrite files outside the intended reference storage directory.
TL;DR
A path traversal flaw in go-git's reference processing allows a malicious remote server to overwrite local repository configuration files (such as .git/config) during clone or fetch operations, potentially leading to arbitrary command execution.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22
- Attack Vector: Network (AV:N)
- CVSS Score: 6.3 (Medium)
- Exploit Status: Proof-of-Concept (PoC)
- Impact: High Integrity (I:H), Low Availability (A:L), Remote Code Execution (RCE)
- KEV Status: Not Listed
Affected Systems
- Applications utilizing github.com/go-git/go-git/v5 prior to v5.19.2 with filesystem-backed storage engines
- Applications utilizing github.com/go-git/go-git/v6 from v6.0.0-alpha.1 to v6.0.0-alpha.4 with filesystem-backed storage engines
Mitigation Strategies
- Upgrade the go-git library to the latest safe release branch.
- Migrate the repository storage implementation from filesystem-backed storage to in-memory storage.
- Enforce network perimeter access controls to prevent interactions with untrusted or public third-party Git hosting platforms.
Remediation Steps:
- Update your Go project dependencies to pull go-git v5.19.2 or v6.0.0-alpha.5.
- Verify the dependency resolution change in the go.mod and go.sum files.
- Audit internal tools that perform clone or fetch operations, modifying the configuration to leverage storage/memory where appropriate.
References
- GitHub Security Advisory GHSA-qgq7-7hm3-q39j
- Public Proof of Concept Repository
- go-git Pull Request #2247
- go-git Pull Request #2254
Read the full report for CVE-2026-71557 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)