{"id":"CVE-2018-17456","aliases":[],"url":"https://o3.security/vulnerability/CVE-2018-17456","summary":null,"details":"Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive \"git clone\" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.","published":"2018-10-06T14:29:00.300Z","modified":"2026-08-07T14:58:41.395674Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.97356,"percentile":0.99894,"asOf":"2026-09-13"},"cisaKev":null,"exploitsKnown":7,"affectedPackages":[],"fix":{"url":"https://github.com/git/git/commit/1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404","label":"git/git@1a7fd1f"},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00003.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/152173/Sourcetree-Git-Arbitrary-Code-Execution-URL-Handling.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105523"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/107511"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1041811"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3408"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3505"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3541"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0316"},{"type":"ADVISORY","url":"https://marc.info/?l=git&m=153875888916397&w=2"},{"type":"ADVISORY","url":"https://seclists.org/bugtraq/2019/Mar/30"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3791-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4311"},{"type":"ADVISORY","url":"https://www.openwall.com/lists/oss-security/2018/10/06/3"},{"type":"FIX","url":"https://github.com/git/git/commit/1a7fd1fb2998002da6e9ff2ee46e1bdd25ee8404"},{"type":"FIX","url":"https://github.com/git/git/commit/a124133e1e6ab5c7a9fef6d0e6bcb084e3455b46"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45548/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/45631/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:58:41.395674Z"}}