Bug 2541673 (CVE-2026-100419) - CVE-2026-100419 gix-fs: gix-fs: Arbitrary code execution via symlink manipulation during checkout
Summary: CVE-2026-100419 gix-fs: gix-fs: Arbitrary code execution via symlink manipula...
Keywords:
Status: NEW
Alias: CVE-2026-100419
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 22:11 UTC by OSIDB Bzimport
Modified: 2026-09-25 22:17 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 22:11:54 UTC
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the worktree through the symlink for code execution or file manipulation.


Note You need to log in before you can comment on or make changes to this bug.