CVE-2026-40034: Gitoxide
High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only partial configuration in .git/config. An attacker can inject arbitrary shell commands via the update field in .gitmodules that will be executed when Submodule::update() is called on a previously-initialized submodule, enabling remote code execution.
Affected products
- Gitoxide Gitoxide: before 0.5.21 (fixed in 0.5.21)
- Gitoxide Gix: before 0.84.0 (fixed in 0.84.0)
- Gitoxide Gix-Submodule: before 0.29.0 (fixed in 0.29.0)
Published 2026-05-26. Last modified 2026-10-08.