CVE-2025-23040 is a credential disclosure vulnerability in GitHub Desktop caused by improper parsing of data exchanged over the Git credential protocol during clone operations. GitHub Desktop invokes Git for network operations such as cloning, and when authentication is required, Git requests credentials from GitHub Desktop through the git-credential protocol. GitHub Desktop’s credential helper parsing logic incorrectly handled carriage return characters in attacker-controlled remote URLs, allowing protocol fields to be smuggled into the credential request. As a result, GitHub Desktop could misinterpret the request and resolve credentials for a different host than the one Git was actually communicating with. A malicious repository, including one referenced through a submodule, could therefore trigger transmission of stored GitHub credentials or other saved remote-host credentials to an unrelated attacker-controlled host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential disclosure vulnerability in GitHub Desktop that can be exploited via a specially crafted clone URL to obtain stored credentials and OAuth tokens during repository cloning.
A credential leakage vulnerability in GitHub Desktop's trampoline credential helper caused by improper parsing of Git Credential Protocol messages with a multiline regular expression, allowing carriage return smuggling and leakage of credentials to attacker-controlled hosts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.