Link following in go-git - CVE-2026-71556

 

Link following in go-git - CVE-2026-71556

Published: July 31, 2026 / Updated: August 8, 2026


Vulnerability identifier: #VU140594
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-71556
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify files outside the intended worktree path.

The vulnerability exists due to improper link resolution before file access in the worktree filesystem wrapper when performing worktree file operations on attacker-controlled symbolic link paths. A remote attacker can introduce a symbolic link in the worktree and cause the application to perform a write through that path to modify files outside the intended worktree path.

User interaction is required, and exploitation requires the attacker to be able to introduce or control a symbolic link in the worktree.


Affected software

go-git
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Public Cloud Module
amazon-ssm-agent

How to mitigate CVE-2026-71556

Install security update from vendor's website.

go-git - addressed in versions 5.19.2, 6.0.0 alpha.5
amazon-ssm-agent - update to 3.3.5226.0-150000.5.40.1

External References

Related Security Bulletins