What is CVE-2026-71556?
CVE-2026-71556 is a vulnerability in the go-git library where symbolic link resolution in worktree operations (checkout, status, add) is not confined to the worktree boundary. This affects go-git versions prior to 5.19.2 and 6.0.0-alpha.5, potentially allowing a maliciously crafted repository to impact files outside the worktree. Users should update to the patched versions.
Azərbaycanca: CVE-2026-71556 go-git kitabxanasında simvolik keçid (symbolic link) həllindəki zəiflikdir. 5.19.2 və 6.0.0-alpha.5 versiyalarından əvvəlki versiyalarda, worktree əməliyyatları simvolik keçidləri iş sahəsi xaricində həll edir. Bu, zərərli repository vasitəsilə iş sahəsindən kənardakı fayllara təsir etməyə imkan yarada bilər; kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which software library is affected by CVE-2026-71556?
This vulnerability affects the go-git library.
To which versions should the go-git library be updated to mitigate this security flaw?
It is recommended to update the library to versions 5.19.2 or 6.0.0-alpha.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.