{"schema_version":"1.7.5","id":"GHSA-m7cr-m3pv-hgrp","published":"2026-05-19T15:21:01Z","modified":"2026-07-07T20:41:15.384922798Z","aliases":["CVE-2026-45570","GO-2026-5496"],"related":["CGA-4fx8-v7vx-v65m"],"summary":"go-git: Improper single-quote escaping in go-git SSH transport","details":"### Impact\n\n`go-git`'s SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. This diverges from canonical Git, which shell-quotes the path through `sq_quote_buf` so that an embedded `'` becomes the `'\\''` close-escape-reopen sequence and the whole path round-trips as a single quoted argument.\n\nA repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. On SSH servers that evaluate the exec command through a shell (for example a user account whose login shell is `/bin/sh` or `/bin/bash`, or a `ForceCommand` wrapper that re-evaluates `$SSH_ORIGINAL_COMMAND`), those additional tokens execute in that account's command-execution context. SSH servers that tokenize the exec command without shell evaluation, including the canonical `git-shell` setup, are not affected.\n\nThe vulnerable behaviour is on the SSH server side, not in `go-git`: the same bytes can be produced by any SSH client. The change in `go-git` is defense-in-depth that restores parity with canonical Git's wire format and prevents `go-git` from being a vehicle for reaching shell-evaluating servers through attacker-influenced repository paths.\n\n### Patches\n\nUsers should upgrade to a patched version in order to mitigate this issue. The fix ports `sq_quote_buf` from canonical Git into `go-git`'s SSH transport so that the wire output is byte-identical to what `git` itself would send for the same input.\n\nVersions prior to `v5` are likely to be affected, users are recommended to upgrade to a supported go-git version.\n\n### Credit\n\nThanks to @N0zoM1z0 for reporting this to the `go-git` project. :bow:","affected":[{"package":{"name":"github.com/go-git/go-git/v5","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-git/v5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.19.1"}]}],"database_specific":{"last_known_affected_version_range":"<= 5.19.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-m7cr-m3pv-hgrp/GHSA-m7cr-m3pv-hgrp.json"}},{"package":{"name":"github.com/go-git/go-git/v6","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-git/v6"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.0-alpha.4"}]}],"database_specific":{"last_known_affected_version_range":"<= 6.0.0-alpha.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-m7cr-m3pv-hgrp/GHSA-m7cr-m3pv-hgrp.json"}},{"package":{"name":"github.com/go-git/go-git","ecosystem":"Go","purl":"pkg:golang/github.com/go-git/go-git"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"4.7.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-m7cr-m3pv-hgrp/GHSA-m7cr-m3pv-hgrp.json"}}],"references":[{"type":"WEB","url":"https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45570"},{"type":"PACKAGE","url":"https://github.com/go-git/go-git"}],"database_specific":{"cwe_ids":["CWE-116"],"github_reviewed":true,"github_reviewed_at":"2026-05-19T15:21:01Z","nvd_published_at":"2026-05-27T15:16:30Z","severity":"LOW"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L"}]}