CVE-2025-41390
HIGHDescription
An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code execution. An attacker can provide a malicious respository to trigger this vulnerability.
Is your site exposed to CVE-2025-41390?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-41390? +
How severe is CVE-2025-41390? +
How do I check if I'm vulnerable to CVE-2025-41390? +
Related Vulnerabilities
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules …
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an …
GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects …
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model …
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins …
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution …