Bug 2531620 (CVE-2026-89011) - CVE-2026-89011 isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function.
Summary: CVE-2026-89011 isomorphic-git: isomorphic-git: Information disclosure via pro...
Keywords:
Status: NEW
Alias: CVE-2026-89011
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-10 20:04 UTC by OSIDB Bzimport
Modified: 2026-09-10 20:06 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-10 20:04:33 UTC
isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. Attackers controlling a Git server can advertise a specially crafted ref such as '__proto__/corsProxy' to reroute all subsequent network operations through an attacker-controlled proxy, causing isomorphic-git to invoke the victim's onAuth callback and transmit credentials to the attacker when the victim calls getRemoteInfo with an attacker-supplied URL.


Note You need to log in before you can comment on or make changes to this bug.