OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100419

HIGH · CVSS 7 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability in gitoxide gix-fs prior to version 0.23.0 allows attackers to exploit a path validation bypass in the worktree checkout mechanism, enabling them to manipulate symlinks to escape the designated worktree directory. This could lead to unauthorized file writes or code execution outside the intended directory, posing a significant risk to system integrity. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100419
Severity
HIGH
CVSS
7
EPSS
0.15%

Original NVD Description

gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the worktree through the symlink for code execution or file manipulation.