Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6453-1 | libgit2 security update |
Thu, 20 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libgit2
Libgit2 libgit2 |
|
| Vendors & Products |
Libgit2
Libgit2 libgit2 |
Thu, 20 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from .gitmodules. The affected src/libgit2/submodule.c paths include git_submodule_lookup and git_submodule_add_setup. A crafted repository can specify a path such as ../escape-target, and applications that initialize the submodule can create directories outside the repository working tree. This issue is fixed in versions 1.8.6 and 1.9.5. | |
| Title | libgit2: Submodule path traversal | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T19:48:17.848Z
Reserved: 2026-06-09T19:11:53.484Z
Link: CVE-2026-53584
Updated: 2026-08-20T19:48:14.383Z
Status : Received
Published: 2026-08-20T19:16:54.680
Modified: 2026-08-20T20:17:34.427
Link: CVE-2026-53584
No data.
OpenCVE Enrichment
Updated: 2026-08-20T20:30:05Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Debian DSA