#CVE-2025-48384

Vulnerability/Target

2025-08-28 • Lazarus Group (APT38) Targets Crypto Sector with Sophisticated Phishing Campaign

Git mishandles configuration values and submodule paths ending in a carriage return, which can cause a submodule to be checked out to an altered location. If a symlink redirects that location to the submodule hooks directory and the submodule contains an executable post-checkout hook, Git may unintentionally execute the script after checkout. The issue is fixed in Git 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

https://www.cve.org/CVERecord?id=CVE-2025-48384

Tagged Reports

« Back