CVE-2025-23040

CVSS 3.1 Score 6.6 of 10 (medium)

Details

Published Jan 15, 2025
CWE ID 522

Summary

CVE-2025-23040 is a vulnerability affecting GitHub Desktop, an open-source Git development application. The issue arises when a user clones a repository with a maliciously crafted remote URL. An attacker can exploit this vulnerability to gain access to the user's GitHub credentials, including their username and OAuth token. GitHub Desktop relies on Git to perform network operations, and when Git requests authentication for a remote host, it does so using the git-credential protocol. By manipulating the URL, an attacker can cause GitHub Desktop to send credentials for a different host than intended, resulting in secret exfiltration. Users should update to GitHub Desktop 3.4.12 or later to mitigate this risk. Suspecting users are advised to revoke any potentially affected credentials.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share