All verified exploits

CVE-2025-48384 Submodule Carriage-Return Config Confusion (Clone RCE)

CVE-2025-48384 is a critical-severity vulnerability, listed in the CISA KEV catalog. AttackerView checks Git sites for it with a live exploit check.

Deterministic critical Git CISA KEV Added cve-verified-cve-2025-48384

Is my site vulnerable to CVE-2025-48384?

Detects services that clone attacker-influenced repositories with a git build older than the July 2025 fix, where a plain recursive clone runs attacker code. Git strips a trailing carriage return when it reads a config value but does not quote one when it writes it, so a submodule whose recorded path ends in a carriage return gets written into the submodule config and read back as a shorter, different path. A symlink committed at that shorter path redirects the submodule checkout, and because the redirect comes from config rather than the working tree, git writes through it without the usual symlink protections. Point it at the submodule hooks directory, track an executable post-checkout file in the submodule, and git runs that file to finish the very checkout that created it. We prove it by reading our own marker, a product only the target could compute, and the uid of the clone process out of the clone log. Repository importers, CI and build runners, mirrors and docs pipelines are the exposed surface. In the CISA known-exploited catalogue since August 2025. Upgrade git to 2.50.1, 2.49.1, 2.48.2, 2.47.3, 2.46.4, 2.45.4, 2.44.4 or 2.43.7.

Is your app exploitable through CVE-2025-48384?

Scan your domain free