Link following in GitPython - #VU152992
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to move a submodule checkout outside the worktree and corrupt repository state.
The vulnerability exists due to improper link resolution before file access in Submodule.move() when processing a fixed move destination below an attacker-committed intermediate symbolic link. A remote attacker can commit a symbolic link in an untrusted repository to move an initialized submodule checkout to an external directory and corrupt repository state.
User interaction is required for an application to initialize the submodule and call Submodule.move() with the fixed destination. The issue applies where Git materializes tracked symbolic links as real symbolic links.