THREAT OPS › Threat News › [GHSA] GHSA-hr3m-4qwq-3mgc (medium) — GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
[GHSA] GHSA-hr3m-4qwq-3mgc (medium) — GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
GHSA-hr3m-4qwq-3mgc Severity: medium CVE: CVE-2026-50024
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
## Summary
GitHacker through 1.1.7 did not validate path segments parsed from attacker-controlled `.git/HEAD` before joining them onto its output directory. A malicious server could coerce GitHacker into reading a
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-50024cve
- https://githacker.pages.dev/securityurl
- https://drivertom.blogspot.com/2021/08/git.htmlurl
Original source: https://github.com/advisories/GHSA-hr3m-4qwq-3mgc