CVE-2013-2117: Jason A Donenfeld Cgit
Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.
Affected products
- Jason A Donenfeld Cgit: up to and including 0.9.1
- Lars Hjemli Cgit: version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; version 0.6 only; …
Published 2013-08-09. Last modified 2026-06-16.