Impact
GitHacker is a Git repository restoration utility that, in versions 1.1.7 and earlier, reads a ref path specified in the repository’s .git/HEAD file. The add_head_file_tasks routine concatenates segments from that path directly to a temporary logs directory without validation, allowing a malicious server to cause GitHacker to read any local file. Once the file is read, add_hashes_parsed scans it for 40‑character hexadecimal substrings and treats each as a separate .git object request, creating an attacker‑observable existence oracle and disclosing matching hex fragments, although the full file contents are not returned. This flaw combines directory traversal (CWE‑22) and path traversal (CWE‑23).
Affected Systems
The vulnerability affects the open‑source tool GitHacker by WangYihang. Versions 1.1.7 and all earlier releases are susceptible; the issue is fixed in release 1.1.9 and later. No other products or vendors are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1 %, implying an extremely low exploitation probability. The vulnerability is not listed in CISA KEV. An attacker must host a malicious .git repository with a crafted .git/HEAD and lure a victim to run GitHacker against that server. No elevated privileges or special conditions are required on the victim side beyond executing the tool. The attacker can read arbitrary files and perform an existence oracle via hexadecimal fragments, which can aid subsequent attacks.
OpenCVE Enrichment
Github GHSA