git-for-windows
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/19/2026, git-for-windows recorded 1 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, git had the most security vulnerabilities in the git-for-windows ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-62960Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windows | Exploitation statusPublic exploit | FixYes | Affected productgit | Published08/21/2026 | SeverityHigh |
CVE-2026-32631Git for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary servers | Exploitation statusNot known exploited | FixYes | Affected productgit | Published04/15/2026 | SeverityHigh |
CVE-2025-66413Git for Windows leaks NTLM hash when cloning from an attacker-controlled server | Exploitation statusPublic exploit | FixYes | Affected productgit | Published03/10/2026 | SeverityHigh |
CVE-2023-29012Git CMD erroneously executes `doskey.exe` in the current directory, if it exists | Exploitation statusNot known exploited | FixYes | Affected productgit | Published04/25/2023 | SeverityHigh |
CVE-2023-29011Git for Windows's config file of `connect.exe` is susceptible to malicious placing | Exploitation statusNot known exploited | FixYes | Affected productgit | Published04/25/2023 | SeverityHigh |
CVE-2023-25815Git looks for localized messages in the wrong place | Exploitation statusNot confirmed | FixNot confirmed | Affected productgit | Published04/25/2023 | SeverityLow |
CVE-2023-22743Git for Windows' installer is susceptible to DLL side loading attacks | Exploitation statusNot known exploited | FixNot confirmed | Affected productgit | Published02/14/2023 | SeverityHigh |
CVE-2023-23618gitk can inadvertently call executables in the worktree | Exploitation statusNot known exploited | FixYes | Affected productgit | Published02/14/2023 | SeverityHigh |
CVE-2022-41953Git clone remote code execution vulnerability in git-for-windows | Exploitation statusNot known exploited | FixNot confirmed | Affected productgit | Published01/17/2023 | SeverityHigh |
CVE-2022-31012Git for Windows' installer can be tricked into executing an untrusted binary | Exploitation statusNot known exploited | FixNot confirmed | Affected productgit | Published07/12/2022 | SeverityHigh |
CVE-2022-24765Uncontrolled search for the Git directory in Git for Windows | Exploitation statusNot known exploited | FixYes | Affected productgit | Published04/12/2022 | SeverityMedium |