MEDIUM 6.8 GitHub
CVE-2025-24890
gix-sec safe.directory protections absent for elevated administrators
### Summary
In a process run with full administrative rights on Windows, `gix-sec` wrongly treats all locations as trusted, leading to the execution of commands configured in repositories controlled by limited user accounts.
### Details
In a similar way to Git, gitoxide tries to avoid operating in local repositories that it neither considers to be owned by the current user nor finds to match any value of `safe.directory`. [This is because](https://git-scm.com/docs/git.html#_security) of the n
Affected Products
- rust/gix-sec <= 0.13.2
References
- https://github.com/advisories/GHSA-7rhf-42qf-vrvc
- https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-7rhf-42qf-vrvc
- https://github.com/GitoxideLabs/gitoxide/commit/39e37482d6f
- https://github.com/advisories/GHSA-7rhf-42qf-vrvc
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-09-09 via GitHub. Affected: rust/gix-sec <= 0.13.2.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.