Description
GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/, allowing a malicious server to make GitHacker read an arbitrary local file when a victim runs the tool against the server's URL. add_hashes_parsed then scans the file for 40-character hexadecimal substrings and requests each match through .git/objects using the first two characters and remaining characters as path components, creating an attacker-observable existence oracle and disclosing matching hexadecimal fragments. Complete file contents are not returned, and the add_folder and add_task write path in shipped version 1.1.7 does not permit an escape. This issue is fixed in repository version 1.1.9.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote directory traversal enabling local file disclosure and existence oracle
Action: Patch
AI Analysis

Impact

GitHacker is a Git repository restoration utility that, in versions 1.1.7 and earlier, reads a ref path specified in the repository’s .git/HEAD file. The add_head_file_tasks routine concatenates segments from that path directly to a temporary logs directory without validation, allowing a malicious server to cause GitHacker to read any local file. Once the file is read, add_hashes_parsed scans it for 40‑character hexadecimal substrings and treats each as a separate .git object request, creating an attacker‑observable existence oracle and disclosing matching hex fragments, although the full file contents are not returned. This flaw combines directory traversal (CWE‑22) and path traversal (CWE‑23).

Affected Systems

The vulnerability affects the open‑source tool GitHacker by WangYihang. Versions 1.1.7 and all earlier releases are susceptible; the issue is fixed in release 1.1.9 and later. No other products or vendors are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1 %, implying an extremely low exploitation probability. The vulnerability is not listed in CISA KEV. An attacker must host a malicious .git repository with a crafted .git/HEAD and lure a victim to run GitHacker against that server. No elevated privileges or special conditions are required on the victim side beyond executing the tool. The attacker can read arbitrary files and perform an existence oracle via hexadecimal fragments, which can aid subsequent attacks.

Generated by OpenCVE AI on September 20, 2026 at 16:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GitHacker to version 1.1.9 or later, which eliminates the vulnerable code paths.
  • If an immediate upgrade is not possible, restrict the use of GitHacker to trusted, internal .git repositories and avoid connecting to external or unknown sources.
  • Apply an input‑validation patch to the add_head_file_tasks routine that rejects '..' components or otherwise ensures the joined path remains within the intended temporary logs directory.

Generated by OpenCVE AI on September 20, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hr3m-4qwq-3mgc GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wangyihang
Wangyihang githacker
Vendors & Products Wangyihang
Wangyihang githacker

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/, allowing a malicious server to make GitHacker read an arbitrary local file when a victim runs the tool against the server's URL. add_hashes_parsed then scans the file for 40-character hexadecimal substrings and requests each match through .git/objects using the first two characters and remaining characters as path components, creating an attacker-observable existence oracle and disclosing matching hexadecimal fragments. Complete file contents are not returned, and the add_folder and add_task write path in shipped version 1.1.7 does not permit an escape. This issue is fixed in repository version 1.1.9.
Title GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via a malicious .git server
Weaknesses CWE-22
CWE-23
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wangyihang Githacker
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:48:33.323Z

Reserved: 2026-06-02T22:46:02.580Z

Link: CVE-2026-50024

cve-icon Vulnrichment

Updated: 2026-09-16T15:48:10.594Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:12.387

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-50024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-23

    Relative Path Traversal