CVE-2025-50178 - CVE House
Back to Database
Status published Medium CVE-2025-50178

GitForge.jl lacks validation for user provided fields

Vulnerability Description

GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for user provided values in certain functions. In the `GitForge.get_repo` function for GitHub, the user can provide any string for the owner and repo fields. These inputs are not validated or safely encoded and are sent directly to the server. This means a user can add path traversal patterns like `../` in the input to access any other endpoints on api.github.com that were not intended. Version 0.4.3 contains a patch for the issue. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-50178

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

GitForge.jl
Vulnerable Versions:
< 0.4.3

Timeline

Official Publish: June 25th, 2025
Last Modified: June 25th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)