CVE-2025-48384 is a high-severity vulnerability in the Git client (on macOS and Linux) disclosed on July 8, 2025.
It occurs when using git clone --recursive on a repository with a manipulated .gitmodules file containing paths ending with a carriage return (CR) character, which can lead to arbitrary file writing and potentially remote code execution (RCE). This poses a significant supply chain risk to developers and automation systems.
| Date | 2025-08-28 09:44:54 |
| Information |
|
Technical Summary
The Git configuration parser strips trailing CRLFs when reading configuration values, but it does not quote the values when writing them, causing discrepancies. If a submodule path ends with a CR character, Git may initialize the module in an unintended location. In the presence of a symlink to the submodule’s hooks directory and an executable post-checkout hook, cloning the repository can trigger the hook—leading to code execution.
Git CLI versions prior to the patched releases—v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1—are vulnerable. It is important to note that Windows systems are not affected.
Furthermore, publicly available proof-of-concept (PoC) exploits exist, increasing the concrete risk.
Recommendations
Update the Git CLI immediately
Ensure all Git clients on macOS and Linux are updated to one of the patched versions:
v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, or v2.50.1 (or later).Avoid recursive cloning from untrusted repositories
Avoid usinggit clone --recursivefor repositories from unverified sources—especially on development workstations or CI/CD pipelines.Use patched versions of Git in automation environments
In environments such as GitLab Runner or CI tools, ensure the Git client used in base images is updated; avoid using vulnerable versions.Check for vulnerable versions
On affected systems, rungit --versionto verify if the installed version is among the safe ones. On macOS, keep in mind that tools like Homebrew may install an additional version of Git without replacing the system one—update your PATH accordingly.Monitor and inform developers
Raise team awareness regarding the risks associated with malicious submodules and ensure that sensitive environments restrict operations to trusted sources only.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
