{"id":"CVE-2024-35186","aliases":["GHSA-7w47-3wg8-547c","RUSTSEC-2024-0348","RUSTSEC-2024-0349","RUSTSEC-2024-0350"],"url":"https://o3.security/vulnerability/CVE-2024-35186","summary":"gix traversal outside working tree enables arbitrary code execution","details":"gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads to a major loss of confidentiality, integrity, and availability, but creating files outside a working tree without attempting to execute code can directly impact integrity as well. This vulnerability has been patched in version(s) 0.36.0.","published":"2024-05-23T08:55:20.653Z","modified":"2026-08-12T03:51:12.379173297Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00816,"percentile":0.54078,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"gix-worktree-state","fixedVersion":"0.11.0"},{"ecosystem":"crates.io","name":"gitoxide","fixedVersion":"0.36.0"},{"ecosystem":"crates.io","name":"gix-fs","fixedVersion":"0.11.0"},{"ecosystem":"crates.io","name":"gix-worktree","fixedVersion":"0.34.0"},{"ecosystem":"crates.io","name":"gix","fixedVersion":"0.63.0"},{"ecosystem":"crates.io","name":"gitoxide-core","fixedVersion":"0.38.0"},{"ecosystem":"crates.io","name":"gix-index","fixedVersion":"0.33.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/Byron/gitoxide/security/advisories/GHSA-7w47-3wg8-547c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35186.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35186"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.379173297Z"}}