This advisory has been withdrawn because it is a duplicate of GHSA-f26g-jm89-4g65. This link is maintained to preserve external references.
gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
{
"cwe_ids": [
"CWE-77"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-30T17:40:48Z",
"nvd_published_at": "2026-05-26T15:16:35Z",
"severity": "HIGH"
}