Link following in GitHub Desktop - #VU152207
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute commands with the user's privileges.
The vulnerability exists due to improper link resolution before file access in the repository-root .gitignore handling helper when processing repository-derived ignore rules. A remote attacker can provide a repository containing a root .gitignore symbolic link and crafted path data to cause content to be appended to a file outside the clone.
Exploitation requires the user to invoke an affected ignore action, symbolic-link support to be enabled, and another application to interpret the modified external file.