GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commits into the pack sent to GitHub, commits that aren’t pointed to by any branch. Although these “hidden” commits never show up in the repository’s visible history, GitHub still serves them at their direct commit URLs. This lets an attacker exfiltrate sensitive data without ever leaving a trace in the branch view. We rate this a High‑impact vulnerability because it completely compromises repository confidentiality. This is fixed in version 1.19.2.
History

Fri, 01 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Finos gitproxy
CPEs cpe:2.3:a:finos:gitproxy:*:*:*:*:*:*:*:*
Vendors & Products Finos gitproxy

Thu, 31 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 31 Jul 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Finos
Finos git-proxy
Vendors & Products Finos
Finos git-proxy

Wed, 30 Jul 2025 21:30:00 +0000

Type Values Removed Values Added
Description GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commits into the pack sent to GitHub, commits that aren’t pointed to by any branch. Although these “hidden” commits never show up in the repository’s visible history, GitHub still serves them at their direct commit URLs. This lets an attacker exfiltrate sensitive data without ever leaving a trace in the branch view. We rate this a High‑impact vulnerability because it completely compromises repository confidentiality. This is fixed in version 1.19.2.
Title GitProxy is susceptible to a hidden commits injection attack
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-30T21:14:41.238Z

Updated: 2025-07-31T17:55:46.333Z

Reserved: 2025-07-25T16:19:16.094Z

Link: CVE-2025-54586

cve-icon Vulnrichment

Updated: 2025-07-31T13:40:03.304Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-30T22:15:25.120

Modified: 2025-08-01T20:03:03.700

Link: CVE-2025-54586

cve-icon Redhat

No data.