CVE-2017-17831: Git Large File Storage Project Git Large File Storage
High severity, CVSS 8.8. EPSS: 3.7% chance of exploitation in the next 30 days.
GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.
Affected products
- Git Large File Storage Project Git Large File Storage: before 2.1.1 (fixed in 2.1.1)
Published 2017-12-21. Last modified 2026-06-17.