Feed/CVE-2024-32002
CVE-2024-32002CRITICALCVSS 9.0

CVE-2024-32002

Published May 14, 2024·Updated Jun 17, 2026

NVD Description

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.

Public Exploits & PoCs52 found

PoC: CVE-2024-32002

CVE-2024-32002 RCE PoC

6

PoC: CVE-2024-32002-Reverse-Shell

Este script demuestra cómo explotar la vulnerabilidad CVE-2024-32002 para obtener una reverse shell, proporcionando acceso remoto al sistema afectado. Úselo con precaución en entornos controlados y solo con fines educativos o de pruebas de seguridad.

2

PoC: CVE-2024-32002

local poc for CVE-2024-32002

2

PoC: CVE-2024-32002-poc

CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。

1

PoC: CVE-2024-32002-PoC

PoC of CVE-2024-32002 - Remote Code Execution while cloning special-crafted local repositories

1

PoC: CVE-2024-32002

RCE through git recursive cloning.

1

PoC: CVE-2024-32002-PoC_Chinese

none

1

PoC: poc-git-rce-cve-2024-32002

poc for git rce using CVE-2024-32002

1

PoC: CVE-2024-32002-hook

hook repo for cve-2024-32002

PoC: CVE-2024-32002

CVE-2024-32002 Private for Capstone Project CC10

PoC: backup-exec-cve-32002

Superproject repo for Backup Exec CVE-2024-32002 exploit

PoC: backup-exec-hook

Submodule repo for Backup Exec CVE-2024-32002 exploit

PoC: cve-2024-32002-poc

Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.

PoC: fuzzy

cve-2024-32002

PoC: Cve-2024-32002-poc

This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.

PoC: CVE-2024-32002

This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.

PoC: hook

Repository for demonstrating CVE-2024-32002 - 2

PoC: captain

Repository for demonstrating CVE-2024-32002

PoC: donald

An example of a repo that would make use of the CVE-2024-32002

PoC: CVE-2024-32002-poc

CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。

PoC: hook_CVE-2024-32002

hihihihaa

PoC: CVE-2024-32002-PoC

Proof of Concept for CVE-2024-32002

PoC: CVE-2024-32002-POC

This is a demo for CVE-2024-32002 POC

PoC: hook

This is a demo for CVE-2024-32002 POC

PoC: CVE-2024-32002

POC

PoC: CVE-2024-32002

adapting CVE-2024-32002 for running offline and locally

PoC: CVE-2024-32002

Just small script to exploit CVE-2024-32002

PoC: CVE-2024-32002

GIT RCE CVE-2024-32002

PoC: CVE-2024-32002

A Reverse shell generator for gitlab-shell vulnerability cve 2024-32002

PoC: git_rce

poc for CVE-2024-32002

PoC: CVE-2024-32002

exploit for CVE-2024-32002

PoC: cve_2024_32002

https://www.cve.org/CVERecord?id=CVE-2024-32002

PoC: wakuwaku

cve-2024-32002yahhh

PoC: CVE-2024-32002

CVE-2024-32002wakuwaku

PoC: rcetest

CVE-2024-32002 poc test

PoC: cve-2024-32002-poc-aw

A POC for CVE-2024-32002 demonstrating arbitrary write into the .git directory.

PoC: cve-2024-32002-submodule-aw

A submodule to demonstrate CVE-2024-32002. Demonstrates arbitrary write into .git.

PoC: hook

part of poc cve-2024-32002

PoC: hook

PoC Exploit for CVE-2024-32002

PoC: CVE-2024-32002

PoC Exploit for CVE-2024-32002

PoC: CVE-2024-32002-

This is the main repository for CVE 2024-32002, and requires recursive cloning because it contains the submodels necessary for execution.

PoC: CVE-2024-32002-hook

CVE-2024-32002-hook

PoC: CVE-2024-32002

Repo for testing CVE-2024-32002

PoC: hook

hook for CVE-2024-32002

PoC: CVE-2024-32002

CVE-2024-32002

PoC: git_rce

CVE-2024-32002 POC

PoC: hook

CVE-2024-32002 hook POC

PoC: hook

CVE-2024-32002-hook

PoC: hook

Hook for the PoC for exploiting CVE-2024-32002

PoC: git_rce

Exploit PoC for CVE-2024-32002

PoC: hooky

A submodule for exploiting CVE-2024-32002 vulnerability.

PoC: CVE-2024-32002

A proof of concept for the git vulnerability CVE-2024-32002

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free