{"id":"CVE-2023-53158","aliases":["GHSA-rrjw-j4m2-mf34","RUSTSEC-2023-0064"],"url":"https://o3.security/vulnerability/CVE-2023-53158","summary":"gix-transport code execution vulnerability","details":"The gix-transport crate before 0.36.1 for Rust allows command execution via the \"gix clone 'ssh://-oProxyCommand=open$IFS\" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.","published":"2025-07-28T00:00:00Z","modified":"2026-08-29T11:46:29.448791489Z","cvss":{"score":4.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00171,"percentile":0.0654,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"gix-transport","fixedVersion":"0.36.1"}],"fix":{"url":"https://github.com/GitoxideLabs/gitoxide/pull/1032","label":"GitoxideLabs/gitoxide#1032"},"references":[{"type":"WEB","url":"https://crates.io/crates/gix-transport"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53158.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rrjw-j4m2-mf34"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53158"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2023-0064.html"},{"type":"FIX","url":"https://github.com/GitoxideLabs/gitoxide/pull/1032"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-29T11:46:29.448791489Z"}}