CVE-2021-21300: high-severity vulnerability in git
malicious repositories can execute remote code while cloning
Published · Updated
Patch soon. It has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
A malicious Git repository can execute code on your computer when you clone it, if you're using Windows or macOS. This happens because the repository uses tricks with symbolic links and file filters (like Git LFS) to run hidden scripts during the cloning process.
A case-insensitive file system (NTFS, HFS+, APFS) combined with symbolic links and configured clean/smudge filters (e.g., Git LFS) allows a malicious repository to execute arbitrary code during clone operations. The attack exploits path collision between symbolic links and filtered files; pre-conditions include Git LFS or similar filters being configured globally and the target system using a case-insensitive filesystem. Impact is remote code execution with the privileges of the cloning user.
In the same product, most dangerous first.