Input validation error in Git Parameter - CVE-2025-53652

 

Input validation error in Git Parameter - CVE-2025-53652

Published: July 29, 2025


Vulnerability identifier: #VU113409
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-53652
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected application does not validate that the Git parameter value submitted to the build matches one of the offered choices. A remote user can inject arbitrary values into Git parameters.


Affected software

Git Parameter

How to mitigate CVE-2025-53652

Install updates from vendor's website.

Git Parameter - update to 444.vca_b_84d3703c2

External References

Related Security Bulletins