Git LFS (git-lfs) – Remote Code Execution (RCE) exploit CVE-2020-27955 – Clone to Pwn

Posted by Dawid Golunski on Nov 05

Go PoC exploit for git-lfs – Remote Code Execution (RCE)
vulnerability CVE-2020-27955

Discovered by Dawid Golunski

Affected (RCE exploit):
Git / GitHub CLI / GitHub Desktop / Visual Studio / GitKraken /
SmartGit / SourceTree etc.
Basically the whole Windows dev world which uses git.

Compile: go build…

Original Source