THREAT OPS › Threat News › [GHSA] GHSA-7rhf-42qf-vrvc (medium) — gix-sec safe.directory protections absent for elevated administrators
[GHSA] GHSA-7rhf-42qf-vrvc (medium) — gix-sec safe.directory protections absent for elevated administrators
GHSA-7rhf-42qf-vrvc Severity: medium CVE: CVE-2025-24890
gix-sec safe.directory protections absent for elevated administrators
### Summary
In a process run with full administrative rights on Windows, `gix-sec` wrongly treats all locations as trusted, leading to the execution of commands configured in repositories controlled by limited user accounts.
### Details
In a similar way to Git, gitoxi
MITRE ATT&CK techniques
- PowerShellT1059.001
Indicators of compromise
- ffb73b5f69dbe86ff88f1c473af65f368a6bcbe5sha1
- CVE-2025-24890cve
- CVE-2022-24765cve
- https://git-scm.com/docs/git.html#_securityurl
Original source: https://github.com/advisories/GHSA-7rhf-42qf-vrvc