Arbitrary code execution via untrusted fsmonitor configuration
Published Oct 20, 2025 · Updated Oct 20, 2025
Code execution in Truffle Security TruffleHog 3.90.2 allows attackers to run commands by scanning a crafted local Git repository. The Git scanner invokes the Git client with repository-local configuration enabled, causing Git to execute a command supplied through core.fsmonitor in .git/config. Exploitation requires a user or automation to scan a repository copied file-for-file rather than cloned, after which commands run with the scanner process's privileges.
Summary
What happened
Code execution in Truffle Security TruffleHog 3.90.2 allows attackers to run commands by scanning a crafted local Git repository. The Git scanner invokes the Git client with repository-local configuration enabled, causing Git to execute a command supplied through core.fsmonitor in .git/config. Exploitation requires a user or automation to scan a repository copied file-for-file rather than cloned, after which commands run with the scanner process's privileges.
The record
- CVE
- CVE-2025-41390
- Published
- Oct 20, 2025
- Updated
- Oct 20, 2025
- Vendor
- Truffle Security
- Product
- TruffleHog
- Classifications
- CWE-829, T1204.002
- Attack vector
- local
- Privileges
- unauthenticated
Timeline
How it unfolded
- Oct 20, 2025CVE publishedPublication date reported by the CVE source.
- Oct 20, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=3.90.2
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Cisco Talos core.fsmonitor TruffleHog demonstrationproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo