CVE-2018-11235 is a directory-traversal vulnerability in Git submodule handling. When cloning a malicious repository recursively, Git obtains submodule names from the repository’s .gitmodules file and appends them to the modules directory path. A name containing traversal sequences can cause Git to use an unintended directory. An attacker can place a post-checkout hook in the resulting submodule location; Git executes that hook, defeating the intended restriction against obtaining hooks from remote repositories and allowing arbitrary script execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a Bash script (`exploit.sh`) and a short README describing usage. The script automates building and hosting a malicious Git repository to exploit CVE-2018-11235 (Git submodule path traversal leading to hook placement and code execution when cloning with `--recurse-submodules`). Key behavior in `exploit.sh`: - Requires root; installs `apache2` and `git` via `apt-get` if missing, enables Apache modules, ensures default site is enabled, and restarts Apache. - Creates a bare repo at `/var/www/html/malicious.git`, clones it into a temp workdir, and constructs a crafted submodule layout (`fakegit/modules/...`). - Adds two submodules pointing to `https://github.com/pentesterlab/empty.git`, then moves the `evil` submodule’s module directory into `fakegit/modules/evil`. - Writes a malicious `post-checkout` hook into `fakegit/modules/evil/hooks/post-checkout` containing the payload `echo "rce-poc-rezydev" > /exploited.txt`. - Abuses `.gitmodules` by renaming/forcing a submodule section name containing `.../../fakegit/modules/evil` to trigger traversal behavior in vulnerable Git versions; also patches `evil/.git` to reference `fakegit/`. - Pushes the crafted content to the bare repo and runs `git update-server-info` so it can be cloned over “dumb” HTTP. Overall purpose: an attacker-side automation tool that sets up an HTTP-served malicious git repository; victims running a vulnerable Git client and cloning with recursive submodules will execute the embedded hook, achieving PoC RCE (marker file creation).
This repository is a proof-of-concept (PoC) exploit for CVE-2018-11235, a critical vulnerability in Git that allows arbitrary code execution when cloning a malicious repository with submodules. The repository contains a build script (build.sh) that constructs a specially crafted Git repository structure. This structure abuses submodule configuration and symlinks to place a malicious post-checkout hook (evil.sh) in a submodule's hooks directory. When a victim clones the repository with the --recurse-submodules flag, the malicious hook is executed, demonstrating code execution (in this PoC, it prints the hostname of the victim's machine). The exploit targets vulnerable versions of Git prior to the fix for CVE-2018-11235. The repository does not contain a pre-built malicious repo due to GitHub restrictions; instead, users must run the build.sh script to generate it. The main payload is a simple shell script, but the technique could be used for more serious attacks. The repository structure is minimal, with a README explaining the exploit, a build script, the payload script, and a .gitignore file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.