CVE-2026-71557 is a path-traversal vulnerability in the filesystem-backed reference storage handling of the Go go-git library. In versions before 5.19.2 and 6.0.0-alpha.5, go-git constructs on-disk reference paths from reference names without sanitizing them. An attacker-controlled reference name containing directory-traversal sequences can therefore cause writes outside the intended Git reference-storage directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, safe local proof-of-concept for CVE-2026-71557 affecting go-git filesystem-backed reference storage. It contains 6 files: two READMEs (English and Japanese), Go module metadata, the main PoC source file (poc.go), and a Bash helper script for version comparison. The core exploit logic is in poc.go. It creates a temporary sandbox directory, initializes a .git directory using go-git's filesystem storage backend, writes a benign marker into .git/config, then calls storage.SetReference with a crafted reference name refs/heads/../../config and a fixed hash value. On vulnerable versions, path normalization causes the reference write to escape the refs subtree and overwrite .git/config with the hash content. The program then reads .git/config back and classifies the result as vulnerable, fixed, or inconclusive. No remote Git server is contacted, no arbitrary commands are executed, and the target is only a temporary local repository created by the PoC. The helper script scripts/run-version-matrix.sh automates testing against two versions of go-git by creating temporary Go modules, copying poc.go into them, fetching go-git v5.19.1 and v5.19.2 respectively, and running the PoC with expected outcomes. This demonstrates regression behavior: vulnerable on v5.19.1 and fixed on v5.19.2. Exploit capability: metadata/file overwrite within a Git repository's .git directory via crafted reference-name path traversal. The practical upstream threat model described in the README is a malicious Git server advertising a traversal-containing reference name that reaches filesystem-backed storage during clone/fetch, but this repository does not implement that network delivery path. As provided, it is a local PoC that directly exercises the vulnerable API entry point. Overall, this is a legitimate PoC exploit repository rather than a detection-only script. It is not weaponized: the payload is fixed and the code is intended to safely demonstrate the overwrite condition in a disposable local environment.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A go-git path-traversal flaw in reference-name handling that enables malicious reference names to write files outside the intended reference-storage directory.
A path-manipulation vulnerability in github.com/go-git/go-git/v5 where malicious reference names can modify files outside reference storage, affecting amazon-ssm-agent.
A file-modification vulnerability in github.com/go-git/go-git/v5 in which malicious Git reference names can modify files outside intended reference storage. It affects the amazon-ssm-agent package on SUSE SLES15 / SLES_SAP15 systems covered by SUSE-SU-2026:4082-1.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.