Description
gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs, gix_sec::identity::is_path_owned_by_current_user obtains folder_owner and token_owner, but its administrator-specific IsWellKnownSid and CheckTokenMembership checks examine the running token rather than confirming the directory owner. This bypasses safe.directory-style protection for repositories owned and configured by a limited user, allowing repository configuration or hooks to execute commands with the administrator's privileges when an affected operation is performed. Exploitation requires Windows, an elevated administrator, a program that relies on gix-sec trust results, and interaction with a repository controlled by another user. An unelevated UAC process is not affected, and cloning is not affected because repository configuration and hooks are not copied. This issue is fixed in version 0.13.3.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Safe.Directory Bypass
Action: Patch
AI Analysis

Impact

gitoxide, a Rust-based implementation of Git, includes the gix-sec crate which on Windows incorrectly treats repositories owned by another user as trusted when a program runs under an elevated administrator token. The flaw lies in gix-sec/src/identity.rs, where the function gix_sec::identity::is_path_owned_by_current_user obtains the directory owner and the token owner, but the administrator‑specific IsWellKnownSid and CheckTokenMembership checks only examine the running token instead of verifying ownership. This bypasses the safe.directory‑style protection that should prevent configurations or hooks from a non‑privileged user’s repository from executing with administrator privileges during certain operations. The vulnerability can be exploited when an administrator runs a gitoxide‑dependent program against a repository owned by a limited user, allowing execution of commands with elevated rights. The issue is fixed by upgrading to version 0.13.3 or later.

Affected Systems

GitoxideLabs’ gitoxide implementation of Git for Windows contains the vulnerable gix-sec crate in all releases prior to 0.13.3. Any system using those builds and executing gitoxide operations under an elevated administrator account is affected, regardless of the user who owns the repository.

Risk and Exploitability

The vulnerability has a CVSS score of 6.8 and an EPSS score of < 1 %, indicating moderate likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires a Windows environment, an elevated administrator token, a program that relies on gix-sec trust results, and interaction with a repository controlled by another user. An unelevated UAC process or cloning of a repository from another user is not affected. The risk is most pronounced when an administrator performs operations on a repository owned by a different user, enabling arbitrary code execution with administrative privileges.

Generated by OpenCVE AI on September 21, 2026 at 00:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade gitoxide to version 0.13.3 or later, which disables the trust bypass for elevated administrators.
  • If upgrading is not immediately possible, restrict administrative use of gitoxide or access to the affected application to avoid running operations against repositories owned by other users.
  • Audit existing repositories for potentially malicious hooks or configuration files and remove or neutralize them before allowing administrative operations.
  • Implement least‑privilege file system permissions so that administrative processes do not have write access to directories owned by other users, deterring accidental exploitation.

Generated by OpenCVE AI on September 21, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7rhf-42qf-vrvc gix-sec safe.directory protections absent for elevated administrators
History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-648
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Gitoxidelabs
Gitoxidelabs gitoxide
Vendors & Products Gitoxidelabs
Gitoxidelabs gitoxide

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs, gix_sec::identity::is_path_owned_by_current_user obtains folder_owner and token_owner, but its administrator-specific IsWellKnownSid and CheckTokenMembership checks examine the running token rather than confirming the directory owner. This bypasses safe.directory-style protection for repositories owned and configured by a limited user, allowing repository configuration or hooks to execute commands with the administrator's privileges when an affected operation is performed. Exploitation requires Windows, an elevated administrator, a program that relies on gix-sec trust results, and interaction with a repository controlled by another user. An unelevated UAC process is not affected, and cloning is not affected because repository configuration and hooks are not copied. This issue is fixed in version 0.13.3.
Title gix-sec safe.directory protections absent for elevated administrators
Weaknesses CWE-283
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Gitoxidelabs Gitoxide
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:00:54.132Z

Reserved: 2025-01-27T15:32:29.450Z

Link: CVE-2025-24890

cve-icon Vulnrichment

Updated: 2026-09-14T19:00:34.702Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:05.117

Modified: 2026-09-23T17:17:44.607

Link: CVE-2025-24890

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T15:28:03Z

Links: CVE-2025-24890 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-283

    Unverified Ownership

  • CWE-648

    Incorrect Use of Privileged APIs