CVE-2024-52005 is a terminal escape-sequence injection vulnerability in Git's handling of remote sideband messages during clone, fetch, and push operations. Git prefixes informational and error messages from the remote process with "remote:" and writes them directly to standard error without neutralizing ANSI escape sequences. When standard error is displayed in a terminal that interprets these sequences, attacker-controlled messages can manipulate the displayed output, conceal or misrepresent information, and mislead users into executing untrusted scripts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive Proof-of-Concept (PoC) for CVE-2024-52005, a high-severity vulnerability in Git that allows ANSI escape sequence injection via the sideband channel. The exploit targets systems (notably DHI container images such as ArgoCD, Jenkins, GitLeaks, etc.) that use vulnerable versions of Git and perform operations on untrusted repositories. The main exploit script (exploit_cve_2024_52005.py) provides a framework to generate malicious repositories and Git hooks with a variety of payloads, including color manipulation, hidden/invisible text, cursor movement, screen clearing, and social engineering messages. Supporting shell scripts (docker-test.sh, test_ansi_injection.sh) automate the process of creating test repositories, injecting malicious hooks, and verifying exploitation within containerized environments. The exploit demonstrates real-world attack scenarios such as CI/CD log poisoning, hiding vulnerabilities, and tricking users into running malicious commands. Multiple endpoints are referenced, including file paths for logs and repositories, as well as URLs used in social engineering payloads. The repository is well-documented, with detailed technical and quickstart guides, and is intended for authorized security testing and responsible disclosure.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The supplied CVSS vectors describe a network-accessible vulnerability requiring user interaction, with high confidentiality, integrity, and availability impacts. Exploits are reported as available, and a patch publication date of January 28, 2026 is listed. The content does not identify the affected product or explain the underlying flaw.
A vulnerability tracked as CVE-2024-52005, addressed by a CentOS/TuxCare security update. The provided CVSS vectors indicate a network-reachable issue requiring user interaction, with high confidentiality, integrity, and availability impact. The content states that exploits are available.
Высокоопасная сетевая уязвимость ANSI escape-sequence injection в sideband-сообщениях Git. Злоумышленник, контролирующий удалённый Git-сервер либо имеющий возможность MITM, может отправлять терминальные управляющие последовательности при clone, fetch или push.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.