CVE-2026-62960
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are treated as local filesystem paths, and file URI prefixes are removed, so a bare UNC path or file URI targeting an attacker-controlled share causes Windows to initiate an outbound SMB connection. This can expose NTLM authentication material to the attacker-selected host. This issue is fixed in version 2.55.0.windows.4.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-200, CWE-610
- Published
- 2026-08-21
- Last modified
- 2026-08-26
Affected products
- git-for-windows git
Weakness type
Related vulnerabilities
- CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets
- CVE-2026-87820 — CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner
- CVE-2026-87810 — Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock
- CVE-2026-87032 — Tanium addressed an information disclosure vulnerability in Tanium Server.
- CVE-2026-87035 — Tanium addressed an information disclosure vulnerability in Comply.
- CVE-2026-87593 — Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87437 — Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87477 — Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak...