/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2025-22620

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-22620

CGA ID

CGA-4vwp-c7cq-2f9w

Severity

Unknown

Description

gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them appropriately. But one of the strategies it uses to set permissions is not subject to the umask. This causes files in a repository to be world-writable in some situations. This vulnerability is fixed in 0.17.0.

References

  • https://images.chainguard.dev/security/CGA-4vwp-c7cq-2f9w

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs