Impact
gitoxide before version 0.38.2 does not validate carriage return characters in URLs that are passed to credential helpers, allowing an attacker to insert malicious CR characters that cause the helper protocol to inject new fields. This field injection can lead to the credential helper returning credentials for an attacker‑chosen host rather than the intended URL, effectively leaking stored credentials to the attacker. The weakness is an input validation flaw (CWE‑116).
Affected Systems
The vulnerability affects all installations of GitoxideLabs' gitoxide software before update to version 0.38.2. Users running older versions of the command‑line client should consider them at risk until a fixed release is applied.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity impact, and the EPSS score is not available, indicating lack of data on exploitation probability. Based on the description, it is inferred that the attack requires the attacker to supply a URL containing a carriage return to a credential helper invocation, and this typically occurs in a controlled or locally compromised environment. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no public exploits have been reported at the time of this analysis.
OpenCVE Enrichment