Link following in go-git - CVE-2026-71556
Published: July 31, 2026 / Updated: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify files outside the intended worktree path.
The vulnerability exists due to improper link resolution before file access in the worktree filesystem wrapper when performing worktree file operations on attacker-controlled symbolic link paths. A remote attacker can introduce a symbolic link in the worktree and cause the application to perform a write through that path to modify files outside the intended worktree path.
User interaction is required, and exploitation requires the attacker to be able to introduce or control a symbolic link in the worktree.
Affected software
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
amazon-ssm-agent
How to mitigate CVE-2026-71556
amazon-ssm-agent - update to 3.3.5226.0-150000.5.40.1