NVD HIGH: CVE-2026-100419 — gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in...
gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_existing enabled, attackers can craft malicious repository trees where symlink entries replace validated directories, causing subsequent files to be written outside the
CVE-2026-100419