CVE-2020-27955 is a critical remote code execution vulnerability in Git Large File Storage (Git LFS) versions 2.12.0 and earlier on Windows. The flaw arises from improper path handling when Git LFS invokes the git binary, failing to specify the full path. This allows an attacker to craft a malicious repository containing a rogue git executable (e.g., git.bat, git.exe, git.cmd). When a victim clones such a repository using a vulnerable Git client or IDE, the malicious executable is invoked, leading to arbitrary code execution. The vulnerability affects a wide range of Git clients and IDEs on Windows, including GitHub CLI, GitHub Desktop, SmartGit, SourceTree, GitKraken, and Visual Studio Code. Unix systems are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module (modules/exploits/windows/http/git_lfs_rce.rb) that exploits CVE-2020-27955, a remote code execution vulnerability in Git LFS (Large File Storage) on Windows. The exploit works by hosting a malicious Git repository and serving it over HTTP. When a vulnerable Windows user clones this repository using a susceptible version of Git and Git LFS, the exploit delivers a malicious payload (by default, a Meterpreter reverse shell) that is executed on the victim's machine. The module checks the User-Agent to ensure the target is running a vulnerable version of Git/Git LFS on Windows before proceeding. The exploit leverages Metasploit's HTTP server capabilities to serve both the malicious repository and the payload. The only file in the repository is the Metasploit module itself, written in Ruby, and it is fully operational, providing remote code execution on successful exploitation. No hardcoded IPs or domains are present; the endpoints are dynamically generated for each run.
This repository contains a proof-of-concept exploit for CVE-2020-27955, a remote code execution vulnerability in Git LFS affecting various Git clients on Windows. The exploit consists of a batch script (git.bat) and a PowerShell reverse shell payload (revsh_powersh.ps1). The batch script demonstrates code execution by creating a file ('GITHACKED') and then launches the PowerShell script, which connects back to the attacker's server (deelmind.lab:1337) to provide a reverse shell. The exploit targets users who clone or interact with a malicious repository using a vulnerable Git client. The repository also includes a small data file (big-bug-lfs-file.dat) and documentation in README.md. The main attack vector is local code execution triggered by user interaction with a malicious repository, leading to remote access for the attacker.
This repository is a proof-of-concept exploit for CVE-2020-27955, a remote code execution vulnerability in Git LFS affecting various Git clients on Windows. The exploit consists of a batch script (git.bat) and a PowerShell script (revsh_powersh.ps1). The batch file demonstrates code execution by creating a test file and then launching the PowerShell script, which opens a reverse shell to 127.0.0.1:1337. The attacker can modify the IP and port in the PowerShell script to receive a shell on their own system. The exploit targets users who clone or interact with a malicious repository using a vulnerable Git client. The repository also includes a small LFS data file and documentation. The main entry point is git.bat, which orchestrates the attack. The exploit is operational and demonstrates real code execution, but the payload is basic and requires manual adjustment for remote exploitation.
This repository contains a Go-based proof-of-concept exploit for CVE-2020-27955, a remote code execution vulnerability affecting Git LFS on Windows. The exploit consists of a single Go source file ('git-lfs-RCE-exploit-CVE-2020-27955.go') and a README with usage instructions and background. The exploit works by compiling the Go file as 'git.exe' and committing it to a repository with LFS files. When a victim clones the repository and Git LFS is invoked, the malicious 'git.exe' is executed, which attempts to connect to a TCP listener (reverse shell) on localhost:1337 (for testing; in a real attack, this would be the attacker's IP and port). If the connection is successful, the attacker can execute arbitrary commands on the victim's system. If the connection fails, calc.exe is launched as a benign test. The exploit targets a wide range of Git clients and developer tools on Windows that use Git LFS, including GitHub CLI, GitHub Desktop, Visual Studio Code, SourceTree, SmartGit, and GitKraken. The repository is a functional PoC and not a detection script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.