Critical Vulnerabilities in GitHub Plugins and Git Affecting User Security

Critical Vulnerabilities in GitHub Plugins and Git Affecting User Security

First seen 8 Sep 2026, 19:20 UTC Sploitus 70.5

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been identified affecting GitHub integration in JetBrains IDE and Git version 2.45.0. CVE-2024-37051 allows unauthorized disclosure of GitHub access tokens through malicious pull requests in JetBrains IDE, risking access to private repositories. Users must update their IDE and revoke existing tokens immediately. CVE-2024-32002 enables remote command execution via git clone using vulnerable submodule configurations, requiring specific settings to exploit. Both vulnerabilities pose significant risks to users and organizations relying on these tools for development. Immediate action is recommended to mitigate potential breaches.

Key Points: • CVE-2024-37051 exposes GitHub tokens via malicious pull requests in JetBrains IDE. • CVE-2024-32002 allows remote command execution through vulnerable Git submodules. • Users must update software and revoke tokens to prevent unauthorized access.

Ask AI about this cluster

Timeline

2024-06-10
CVE-2024-37051 published
JetBrains IDE vulnerability disclosed, allowing token exposure through PRs.
Sploitus
2024-06-12
First public PoC for CVE-2024-37051
Proof-of-concept code for the JetBrains IDE vulnerability made public.
Sploitus
Date unknown
CVE-2024-32002 identified
Remote command execution vulnerability discovered in Git version 2.45.0 affecting users with specific configurations.
Sploitus