« Back to list

GIT

GIT LFS: vulnerabilities and CVEs

GIT LFS has 2 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months1
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-58423High (7.7)0.54%—Jul 3, 2026
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2024-53263High (8.5)1.1%—Jan 14, 2025
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it passes portions of the host's URL to the `git-credential(1)` command without checking for embedded…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1078 Valid Accounts1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by GIT