Impact
gitoxide, a Rust-based implementation of Git, includes the gix-sec crate which on Windows incorrectly treats repositories owned by another user as trusted when a program runs under an elevated administrator token. The flaw lies in gix-sec/src/identity.rs, where the function gix_sec::identity::is_path_owned_by_current_user obtains the directory owner and the token owner, but the administrator‑specific IsWellKnownSid and CheckTokenMembership checks only examine the running token instead of verifying ownership. This bypasses the safe.directory‑style protection that should prevent configurations or hooks from a non‑privileged user’s repository from executing with administrator privileges during certain operations. The vulnerability can be exploited when an administrator runs a gitoxide‑dependent program against a repository owned by a limited user, allowing execution of commands with elevated rights. The issue is fixed by upgrading to version 0.13.3 or later.
Affected Systems
GitoxideLabs’ gitoxide implementation of Git for Windows contains the vulnerable gix-sec crate in all releases prior to 0.13.3. Any system using those builds and executing gitoxide operations under an elevated administrator account is affected, regardless of the user who owns the repository.
Risk and Exploitability
The vulnerability has a CVSS score of 6.8 and an EPSS score of < 1 %, indicating moderate likelihood of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires a Windows environment, an elevated administrator token, a program that relies on gix-sec trust results, and interaction with a repository controlled by another user. An unelevated UAC process or cloning of a repository from another user is not affected. The risk is most pronounced when an administrator performs operations on a repository owned by a different user, enabling arbitrary code execution with administrative privileges.
OpenCVE Enrichment
Github GHSA