GHSA-pg4w-g64p-qwhj
## Summary attachments: [pocs.zip](https://github.com/user-attachments/files/26431422/pocs.zip) When `Repository::submodules()` loads submodule metadata, it prefers the worktree `.gitmodules` file if that path exists. In the current implementation, the path is read with `std::fs::read()`, which follows symlinks. As a result, a repository can present a symlinked `.gitmodules` that points outside the repository, and gitoxide will parse the out-of-repository bytes as submodule configuration. This is a repository-boundary violation. A caller using the high-level submodule API can believe it is reading repository-local submodule metadata, while the bytes are actually coming from an arbitrary file outside the repository tree. ## Root cause analysis The relevant flow is: 1. [`gix/src/repository/location.rs`](https://github.com/GitoxideLabs/gitoxide/blob/v0.52.0/gix/src/repository/location.rs) derives the worktree `.gitmodules` path as `workdir/.gitmodules`. 2. [`gix/src/repository/submodule.rs`](https://github.com/GitoxideLabs/gitoxide/blob/v0.52.0/gix/src/repository/submodule.rs) reads that path with `std::fs::read(&path)` and immediately parses the bytes as a submodule configuration file. 3. `Repository::submodules()` exposes the parsed entries through the high-level API. The issue is not in the parser. The issue is that the worktree path is treated as an ordinary file without checking whether it is a symlink, and without checking whether the canonicalized target remains inside the repository worktree. Because `std::fs::read()` follows symlinks, a malicious repository can cause gitoxide to ingest bytes from an attacker-chosen location outside the repository. The resulting `Submodule` objects then expose `name`, `path`, and `url` values derived from that external file. ## Reproduction steps Use the attached PoC zip that contains the `pocs/` workspace. 1. Unzip the PoC archive. 2. Enter `pocs/F001`. 3. Run: ```bash cargo run --quiet ``` 4.
Properties
- ghsa_id
- GHSA-pg4w-g64p-qwhj
- summary
- gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
- severity
- high
- cve_id
- GHSA-pg4w-g64p-qwhj
- is_ghsa_only
- true
- ghsa_published
- 2026-05-05T19:26:09Z
- source_url
- https://github.com/advisories/GHSA-pg4w-g64p-qwhj
- ghsa_updated
- 2026-05-05T19:26:09Z
Related Entities (6)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (2)
AFFECTS (2)
Explore deeper with Ninja Signal's threat intelligence graph