CVE-2014-5023: Gitlist

Medium severity, CVSS 6.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.

Affected products

  • Gitlist Gitlist: affected versions not specified

Published 2014-07-22. Last modified 2026-06-17.