Link following in git-lfs - CVE-2025-26625
Published: November 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to overwrite arbitrary files on the system.
The vulnerability exists due to an insecure link following issue. When populating a Git repository's working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. A remote attacker can write arbitrary files using crafted links, leading to remote code execution.
Affected software
Git for Windows
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Development Tools Module
openSUSE Leap
Ubuntu
Fedora
GitHub Desktop
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
git-lfs (Ubuntu package)
git-lfs (Red Hat package)
ruby (Red Hat package)
git-lfs
git-lfs-doc
How to mitigate CVE-2025-26625
Git for Windows - update to 2.51.1.1
GitHub Desktop - update to 3.5.4
git-lfs (Ubuntu package) - addressed in versions 2.3.4-1ubuntu0.1~esm1, 2.9.2-1ubuntu0.1~esm2, 3.0.2-1ubuntu0.3+esm2, 3.4.1-1ubuntu0.3+esm2, 3.6.1-1ubuntu0.1
git-lfs (Red Hat package) - addressed in versions 2.13.3-3.el8_4.3, 2.13.3-3.el8_6.5, 2.13.3-5.el9_0.5, 3.2.0-2.el8_8.5, 3.2.0-2.el9_2.4, 3.4.1-4.el9_4.3, 3.4.1-6.el8_10, 3.6.1-2.el9_6.1, 3.6.1-2.el10_0.1, 3.6.1-4.el9_7, 3.6.1-4.el10_1
ruby (Red Hat package) - update to 3.3.10-11.el10_0
git-lfs - addressed in versions 3.4.1-6.0.1, 3.7.1-1
git-lfs-doc - addressed in versions 3.4.1-6.0.1, 3.7.1-1
git-lfs - addressed in versions 3.7.1-1.fc41, 3.7.1-1.fc42, 3.7.1-1.fc43
git-lfs - update to 3.7.1-150600.13.6.1
External References
Related Security Bulletins
- Insecure link following in Git LFS
- Git for Windows update for Git LFS
- GitHub Desktop update for Git LFS
- Fedora 41 update for git-lfs
- Fedora 42 update for git-lfs
- Fedora 43 update for git-lfs
- Anolis OS update for git-lfs
- Red Hat Enterprise Linux 9 update for the ruby:3.3 module
- Red Hat Enterprise Linux 10 update for git-lfs
- Red Hat Enterprise Linux 10 update for ruby
- Anolis OS update for git-lfs
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 9 update for git-lfs
- Red Hat Enterprise Linux 10 update for git-lfs
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 8 update for git-lfs
- Red Hat Enterprise Linux 9 update for git-lfs
- Ubuntu update for git-lfs
- SUSE update for git-lfs