{"id":"CVE-2017-17831","aliases":["GHSA-w4xh-w33p-4v29","GO-2021-0073"],"url":"https://o3.security/vulnerability/CVE-2017-17831","summary":"GitHub Git LFS Arbitrary command execution vulnerability","details":"GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a \"url =\" line in a .lfsconfig file within a repository.","published":"2017-12-21T06:29:00.243Z","modified":"2026-07-08T11:35:58.983395Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/git-lfs/git-lfs","fixedVersion":"2.1.1-0.20170519163204-f913f5f9c7c6"}],"fix":{"url":"https://github.com/git-lfs/git-lfs/pull/2242","label":"git-lfs/git-lfs#2242"},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/102926"},{"type":"ADVISORY","url":"https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2018-01-24-942834324.html"},{"type":"ADVISORY","url":"https://github.com/git-lfs/git-lfs/releases/tag/v2.1.1"},{"type":"FIX","url":"https://github.com/git-lfs/git-lfs/pull/2242"},{"type":"EVIDENCE","url":"http://blog.recurity-labs.com/2017-08-10/scm-vulns"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:35:58.983395Z"}}