CVE-2025-26625
Git LFS may write to arbitrary files via crafted symlinks in github.com/git-lfs/git-lfs
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/git-lfs/git-lfs/security/advisories/GHSA-6pvw-g552-53c5, https://github.com/git-lfs/git-lfs/commit/0cffe93176b870055c9dadbb3cc9a4a440e98396, https://github.com/git-lfs/git-lfs/commit/5c11ffce9a4f095ff356bc781e2a031abb46c1a8, https://github.com/git-lfs/git-lfs/commit/d02bd13f02ef76f6807581cd6b34709069cb3615, https://github.com/git-lfs/git-lfs/releases/tag/v3.7.1
