Threat Advisory

go-git Vulnerabilities Impact Symlink Management in Worktree Tasks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in go-git, an extensible Git implementation library written in pure Go. The flaws involve symlink traversal and improper path sanitization issues, allowing attackers to bypass directory boundaries and potentially modify files outside the intended repository or working tree. These issues pose risks to data integrity and system security, particularly for applications that clone repositories from untrusted sources or interact with malicious Git servers.

CVE-2026-71556 (CVSS 7.1 — High): go-git: Worktree operations may follow symlinks, allowing an attacker with normal privileges to access sensitive information. An attacker can exploit this vulnerability by manipulating the file system.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in go-git, an extensible Git implementation library written in pure Go. The flaws involve symlink traversal and improper path sanitization issues, allowing attackers to bypass directory boundaries and potentially modify files outside the intended repository or working tree. These issues pose risks to data integrity and system security, particularly for applications that clone repositories from untrusted sources or interact with malicious Git servers.

CVE-2026-71556 (CVSS 7.1 — High): go-git: Worktree operations may follow symlinks, allowing an attacker with normal privileges to access sensitive information. An attacker can exploit this vulnerability by manipulating the file system.[emaillocker id="1283"]

CVE-2026-71557 (CVSS 6.3 — Medium): go-git: Malicious reference names may modify files outside the reference storage, potentially leading to data corruption or unauthorized changes. An attacker with normal privileges can exploit this vulnerability by providing malicious input.

RECOMMENDATIONS:

  • We recommend you to update github.com/go-git/go-git/v5 and github.com/go-git/go-git/v6 to below version:
  • CVE-2026-71556: https://github.com/advisories/GHSA-hc8v-wwc9-vgxm
  • CVE-2026-71557: https://github.com/advisories/GHSA-qgq7-7hm3-q39j

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu