DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CVE-2025-22620

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-22620

Severity

5.0

Medium

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

Summary

gix-worktree-state nonexclusive checkout sets executable files world-writable

Description

gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject to the umask. This causes files in a repository to be world-writable in some situations. This vulnerability is fixed in 0.17.0.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-22620

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing