Git LFS may write to arbitrary files via crafted symlinks in github.com/git-lfs/git-lfs
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2025-4038" }
"https://vuln.go.dev/ID/GO-2025-4038.json"
{ "imports": [ { "symbols": [ "checkoutCommand", "checkoutConflict", "newSingleCheckout", "singleCheckout.Run" ], "path": "github.com/git-lfs/git-lfs/v3/commands" }, { "symbols": [ "GitFilter.SmudgeToFile" ], "path": "github.com/git-lfs/git-lfs/v3/lfs" } ] }