Description
Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to version 2.19.0
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 24 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tortoisegit
Tortoisegit tortoisegit |
|
| Vendors & Products |
Tortoisegit
Tortoisegit tortoisegit |
Wed, 24 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit | |
| Title | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGit | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-06-24T12:01:06.166Z
Reserved: 2026-06-11T10:19:36.614Z
Link: CVE-2026-11968
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T15:45:06Z
Weaknesses