CVE-2026-53584

EUVD-2026-63546
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from .gitmodules. The affected src/libgit2/submodule.c paths include git_submodule_lookup and git_submodule_add_setup. A crafted repository can specify a path such as ../escape-target, and applications that initialize the submodule can create directories outside the repository working tree. This issue is fixed in versions 1.8.6 and 1.9.5.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libgit2libgit2
𝑥
< 1.8.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
libgit2
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.9.6+ds-1
fixed
sid
1.9.7+ds-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgit2
bionic
ignored
focal
Fixed 0.28.4+dfsg.1-2ubuntu0.1+esm1
released
jammy
Fixed 1.1.0+dfsg.1-4.1ubuntu0.1+esm1
released
noble
Fixed 1.7.2+ds-1ubuntu3.1
released
resolute
Fixed 1.9.1+ds-1ubuntu1.1
released
trusty
ignored
xenial
ignored
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cargo
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
cargo-c
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
cargo-c-debuginfo
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
cargo-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
clippy-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-analyzer-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-cargo-c-debugsource
Amazon Linux 2023
0:0.10.21-1.amzn2023.0.1
fixed
rust-debugger-common
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-debugsource
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-doc
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-gdb
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-lldb
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-src
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-unknown-unknown
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-std-static-wasm32-wasip1
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rust-toolset-srpm-macros
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt
Amazon Linux 2
0:1.97.0-2.amzn2
fixed
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed
rustfmt-debuginfo
Amazon Linux 2023
0:1.97.0-2.amzn2023
fixed