Git LFS may write to arbitrary files via crafted symlinks in github.com/git-lfs/git-lfs
{ "url": "https://pkg.go.dev/vuln/GO-2025-4038", "review_status": "REVIEWED" }
"https://vuln.go.dev/ID/GO-2025-4038.json"
{ "imports": [ { "path": "github.com/git-lfs/git-lfs/v3/commands", "symbols": [ "checkoutCommand", "checkoutConflict", "newSingleCheckout", "singleCheckout.Run" ] }, { "path": "github.com/git-lfs/git-lfs/v3/lfs", "symbols": [ "GitFilter.SmudgeToFile" ] } ] }