In gitoxide versions prior to 0.17.0, specifically in the gix-worktree-state component, executable files checked out from a repository are assigned 0777 permissions. Due to one of the permission-setting strategies not respecting the process umask, this can result in files being created as world-writable, contrary to the intended restriction. This exposes the files to unauthorized modification by any user on the system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) for CVE-2025-22620, a vulnerability in the 'gix-worktree-state' crate (used by the Gitoxide project). The repository contains a minimal Rust project with a main entry point (src/main.rs) that demonstrates the vulnerable behavior by performing a checkout operation on a specially prepared local Git repository ('has-executable'). The included shell script (make-repo) sets up this repository with two files, one of which is marked as executable, to reproduce the conditions necessary for the exploit. The PoC is intended for local demonstration and analysis of the vulnerability, not for weaponization or remote exploitation. The README provides context, links to the advisory, and describes the purpose and branches of the repository. No network endpoints or remote attack vectors are present; the exploit is entirely local and targets a specific version of a Rust crate.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.