THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hr3m-4qwq-3mgc (medium) — GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

[GHSA] GHSA-hr3m-4qwq-3mgc (medium) — GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

highgithub_advisoriesPublished 2026-09-09

GHSA-hr3m-4qwq-3mgc Severity: medium CVE: CVE-2026-50024

GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server

## Summary

GitHacker through 1.1.7 did not validate path segments parsed from attacker-controlled `.git/HEAD` before joining them onto its output directory. A malicious server could coerce GitHacker into reading a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hr3m-4qwq-3mgc