Link following in git-lfs - CVE-2025-26625

 

Link following in git-lfs - CVE-2025-26625

Published: November 11, 2025


Vulnerability identifier: #VU118253
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-26625
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files on the system.

The vulnerability exists due to an insecure link following issue. When populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. A remote attacker can write arbitrary files using crafted links, leading to remote code execution. 


Affected software

git-lfs
Git for Windows
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Development Tools Module
openSUSE Leap
Ubuntu
Fedora
GitHub Desktop
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git-lfs (Ubuntu package)
git-lfs (Red Hat package)
ruby (Red Hat package)
git-lfs
git-lfs-doc

How to mitigate CVE-2025-26625

Install updates from vendor's website.

git-lfs - update to 3.7.1
Git for Windows - update to 2.51.1.1
GitHub Desktop - update to 3.5.4
git-lfs (Ubuntu package) - addressed in versions 2.3.4-1ubuntu0.1~esm1, 2.9.2-1ubuntu0.1~esm2, 3.0.2-1ubuntu0.3+esm2, 3.4.1-1ubuntu0.3+esm2, 3.6.1-1ubuntu0.1
git-lfs (Red Hat package) - addressed in versions 2.13.3-3.el8_4.3, 2.13.3-3.el8_6.5, 2.13.3-5.el9_0.5, 3.2.0-2.el8_8.5, 3.2.0-2.el9_2.4, 3.4.1-4.el9_4.3, 3.4.1-6.el8_10, 3.6.1-2.el9_6.1, 3.6.1-2.el10_0.1, 3.6.1-4.el9_7, 3.6.1-4.el10_1
ruby (Red Hat package) - update to 3.3.10-11.el10_0
git-lfs - addressed in versions 3.4.1-6.0.1, 3.7.1-1
git-lfs-doc - addressed in versions 3.4.1-6.0.1, 3.7.1-1
git-lfs - addressed in versions 3.7.1-1.fc41, 3.7.1-1.fc42, 3.7.1-1.fc43
git-lfs - update to 3.7.1-150600.13.6.1

External References

Related Security Bulletins