CVE-2026-45570: Go-Git Project Go-Git
Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.
Affected products
- Go-Git Project Go-Git: before 5.19.1 (fixed in 5.19.1); version 6.0.0 only
Published 2026-05-27. Last modified 2026-06-17.