H3-2025-0019
Git Repo-Jacking
Category | SECURITY_MISCONFIGURATION |
Base Score | 5.0 |
Description
If a user decides to rename their user account in Github or Gitlab, the git provider will automatically create a redirect from the old name to the new. However, if an attacker creates a new account with the old name, they can potentially inject their own code into your project.
Impact
Attackers can perform a supply chain attack and inject code, deface images or other malicious acts.