Skip to content

H3-2025-0019

Git Repo-Jacking

Category SECURITY_MISCONFIGURATION
Base Score 5.0

Description

If a user decides to rename their user account in Github or Gitlab, the git provider will automatically create a redirect from the old name to the new. However, if an attacker creates a new account with the old name, they can potentially inject their own code into your project.

Impact

Attackers can perform a supply chain attack and inject code, deface images or other malicious acts.

References