Raleigh, NC

32°F
Scattered Clouds Humidity: 79%
Wind: 2.06 M/S

Git Vulnerability Under Attack, CISA Warns

Git Vulnerability Under Attack, CISA Warns

CISA has issued a high-severity alert for CVE-2025-48384, a Git flaw that allows attackers to write arbitrary files by exploiting how Git handles carriage return characters in configuration files. The issue has already been actively exploited. 

The vulnerability lets attackers inject malicious hooks during submodule initialization, leading to unauthorized code execution with user privileges. It poses a serious risk to CI/CD pipelines and automated build systems. 

Organizations are urged to update Git to version 2.50.1 or apply patches for older versions. If patching is delayed, disabling submodule initialization or removing the post-checkout hook is recommended. 

All fixes should be in place by September 15, 2025, to avoid potential data breaches or supply chain attacks. 

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Image

With Cybersecurity Insights, current news and event trends will be captured on cybersecurity, recent systems / cyber-attacks, artificial intelligence (AI), technology innovation happening around the world; to keep our viewers fast abreast with the current happening with technology, system security, and how its effect our lives and ecosystem. 

Please fill the required field.