CVE-2014-0177: GitHub Hub

Low severity, CVSS 3.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.

Affected products

  • GitHub Hub: up to and including 1.12.0

Published 2014-05-27. Last modified 2026-06-17.