Skip to content
Appaloosa Scout
Language selector
fr en

KEV · Actively exploited

CVE-2025-48384

CVE-2025-48384 is actively exploited (CISA KEV catalog) : high severity (CVSS 8.0), 1 tracked app concerned, none still exposed on their current version.

Severity (CVSS)
8.0

NVD scale

Exploitation
Confirmed

CISA KEV · EPSS predicts 4.1 %

Tracked apps
1
Still exposed
0

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1.

Attack vector : Network
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS 4.11% predictive model; CISA confirms active exploitation percentile 90.4%

CISA Known Exploited Vulnerability

Added to KEV
2025-08-25
Remediation deadline
2025-09-15
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware
Unknown (not documented by CISA)

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (9)
Vendor Product Versions
git-scm git
All platforms (wildcard)
<2.43.7
git-scm git
All platforms (wildcard)
≥2.44.0 <2.44.4
git-scm git
All platforms (wildcard)
≥2.45.0 <2.45.4
git-scm git
All platforms (wildcard)
≥2.46.0 <2.46.4
git-scm git
All platforms (wildcard)
≥2.47.0 <2.47.3
git-scm git
All platforms (wildcard)
≥2.48.0 <2.48.2
git-scm git
All platforms (wildcard)
≥2.49.0 <2.49.1
git-scm git
All platforms (wildcard)
≥2.50.0 <2.50.1
apple xcode
All platforms (wildcard)
<26.0
View on NVD ↗ CISA KEV catalog ↗ Advisory · github.com

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM