GitoxideLabs
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 10
en
Verify to analyze this security profile
As of 09/15/2026, GitoxideLabs recorded 10 security vulnerabilities in the last 90 days across 1 products, including 7 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, gitoxide had the most security vulnerabilities in the GitoxideLabs ecosystem, with 10 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2025-24890gix-sec safe.directory protections absent for elevated administrators | Exploitation statusNot confirmed | FixYes | Affected productgitoxide | Published09/14/2026 | SeverityMedium |
CVE-2026-82255gitoxide 0.25.4 HTTP Credential Leak via Redirect | Exploitation statusNot known exploited | FixNot confirmed | Affected productgitoxide | Published08/28/2026 | SeverityHigh |
CVE-2026-82254gitoxide before 0.69.0 Denial of Service via gix-pack | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityHigh |
CVE-2026-82253gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityHigh |
CVE-2026-82252gitoxide before 0.52.1 Repository Boundary Violation via symlinked .gitmodules | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityHigh |
CVE-2026-82251gitoxide before 0.52.1 Path Traversal via Submodule Name | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityHigh |
CVE-2026-82250gitoxide gix-packetline before 0.21.5 Denial of Service | Exploitation statusNot known exploited | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityHigh |
CVE-2026-82249gitoxide before 0.38.2 Credential Helper Protocol Field Injection | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityLow |
CVE-2026-82248gitoxide before 0.33.0 Path Traversal via symlink following | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityMedium |
CVE-2026-82247gitoxide before 0.37.1 HTTP Basic credential leak via URL parsing | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published08/28/2026 | SeverityHigh |
CVE-2026-44471gitoxide: Symlink prefix-reuse allows worktree escape during checkout | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published05/13/2026 | SeverityHigh |
CVE-2026-0810Gix-date: gix-date: undefined behavior due to invalid string generation | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published01/26/2026 | SeverityHigh |
CVE-2023-53158 | Exploitation statusPublic exploit | FixYes | Affected productgix-transport | Published07/28/2025 | SeverityMedium |
CVE-2025-31130gitoxide does not detect SHA-1 collision attacks | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published04/04/2025 | SeverityMedium |
CVE-2025-22620gix-worktree-state nonexclusive checkout sets executable files world-writable | Exploitation statusPublic exploit | FixYes | Affected productgitoxide | Published01/20/2025 | SeverityMedium |