{"id":"CVE-2024-32884","aliases":["GHSA-98p4-xjmm-8mfh","RUSTSEC-2024-0335"],"url":"https://o3.security/vulnerability/CVE-2024-32884","summary":"gix-transport indirect code execution via malicious username","details":"gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by an application whose current working directory contains a malicious file, arbitrary code execution occurs. This is related to the patched vulnerability GHSA-rrjw-j4m2-mf34, but appears less severe due to a greater attack complexity. This issue has been patched in versions 0.35.0, 0.42.0 and 0.62.0.","published":"2024-04-26T18:04:04.374Z","modified":"2026-08-12T03:51:40.044500929Z","cvss":{"score":6.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L"},"epss":{"score":0.00514,"percentile":0.41845,"asOf":"2026-09-04"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"gix-transport","fixedVersion":"0.42.0"},{"ecosystem":"crates.io","name":"gix","fixedVersion":"0.62"},{"ecosystem":"crates.io","name":"gitoxide","fixedVersion":"0.35"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/Byron/gitoxide/security/advisories/GHSA-98p4-xjmm-8mfh"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32884.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32884"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2024-0335.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.044500929Z"}}