{"id":"CVE-2025-21613","aliases":["GHSA-v725-9546-7q7m","GO-2025-3368"],"url":"https://o3.security/vulnerability/CVE-2025-21613","summary":"go-git has an Argument Injection via the URL field","details":"### Impact\nAn argument injection vulnerability was discovered in `go-git` versions prior to `v5.13`. \n\nSuccessful exploitation of this vulnerability could allow an attacker to set arbitrary values to [git-upload-pack flags](https://git-scm.com/docs/git-upload-pack). This only happens when the `file` transport protocol is being used, as that is the only protocol that shells out to `git` binaries.\n\n### Affected versions\nUsers running versions of `go-git` from `v4` and above are recommended to upgrade to `v5.13` in order to mitigate this vulnerability.\n\n### Workarounds\nIn cases where a bump to the latest version of `go-git` is not possible, we recommend users to enforce restrict validation rules for values passed in the URL field.\n\n## Credit\nThanks to @vin01 for responsibly disclosing this vulnerability to us.","published":"2025-01-06T16:13:10.611Z","modified":"2026-08-12T03:51:48.796588775Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"gopkg.in/src-d/go-git.v4","fixedVersion":null},{"ecosystem":"Go","name":"github.com/go-git/go-git/v5","fixedVersion":"5.13.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21613.json"},{"type":"ADVISORY","url":"https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-21613"},{"type":"PACKAGE","url":"https://github.com/go-git/go-git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.796588775Z"}}