CVE-2025-24890: gix-sec safe.directory protections absent for elevated administrators
In a process run with full administrative rights on Windows, gix-sec wrongly treats all locations as trusted, leading to the execution of commands configured in repositories controlled by limited user accounts.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-24890 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →