CVE-2025-54583 HIGH

CVE-2025-54583: GitProxy bypasses approvals when pushing multiple branches

Vendor Finos
Product git-proxy
Weakness CWE-863 · Incorrect authorization
Published July 30, 2025
Last update July 30, 2025

CVSS base score

8.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

What the vulnerability does

01Description

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and plugins are skipped, code containing secrets or unwanted changes could be pushed into a repository. This is fixed in version 1.19.2.

Key dates

02Disclosure timeline

July 30, 2025 CVE published
July 30, 2025 Record updated