Security Research

CVE-2024-32002 Git submodule + symlink RCE: arbitrary code execution via git clone –recursive

#Vulnerability Analysis#Code Audit#Supply Chain Attack
Dark dossier of Git repo submodule and symlink compromise path

When Git performs a recursive clone it executes the submodule’s post-checkout hook. An attacker crafting a malicious repository with a symlink achieves RCE at the clone stage — no exploit shipping required.

Unlock to view this content.