{"id":"CVE-2024-43785","aliases":["GHSA-88g2-r9rw-g55h","RUSTSEC-2024-0364"],"url":"https://o3.security/vulnerability/CVE-2024-43785","summary":"gitoxide-core does not neutralize special characters for terminals","details":"gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does not neutralize newlines, backspaces, or control characters—including those that form ANSI escape sequences—that appear in a repository's paths, author and committer names, commit messages, or other metadata. Such text may be written as part of the output of a command, as well as appearing in error messages when an operation fails. This sometimes allows an untrusted repository to misrepresent its contents and to alter or concoct error messages.","published":"2024-08-22T14:19:31.070Z","modified":"2026-07-15T01:49:16.866623870Z","cvss":{"score":2.5,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"gitoxide-core","fixedVersion":null},{"ecosystem":"crates.io","name":"gitoxide","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/Byron/gitoxide/security/advisories/GHSA-88g2-r9rw-g55h"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/43xxx/CVE-2024-43785.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43785"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:16.866623870Z"}}