Known vulnerabilities in git-lfs
Vendor:
Git LFS
Software:
git-lfs
Software CPE:
cpe:2.3:a:git-lfs:git-lfs:*:*:*:*:*:*:*:*
Website:
https://github.com/git-lfs/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
3.7.1
3.7.0
3.6.1
3.6.0
3.5.1
3.5.0
3.4.1
3.4.0
3.3.0
3.2.0
3.1.4
3.1.3
3.1.2
3.1.1
3.1.0
3.0.2
3.0.1
3.0.0
2.13.3
0.1.0
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.4.1
0.4.2
0.4.2.1
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
1.0.0
1.0.1
1.0.2
1.1.1
1.1.2
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.5.0
2.5.2
2.6.0
2.13.2
2.13.1
2.13.0
2.12.1
2.3.4
2.12.0
2.4.1
2.4.0
2.5.1
2.4.2
1.1.0
2.6.1
2.7.0
2.7.1
2.7.2
2.8.0
2.9.0
2.9.1
2.9.2
2.10.0
2.11.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU118253 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-26625 |
CWE-59 | High | 3.7.1 | 11.11.2025 |
SB2025111128 SB2025111129 SB2025111130 and 19 more |
||
| #VU102873 - Improper input validation CVE-2024-53263 |
CWE-20 | Medium | 3.6.1 | 16.01.2025 |
SB2025011645 SB2025011648 SB2025011649 and 15 more |