2026-09-17
This weekNew web3 security vulnerability disclosures and CVEs in the last 48 hours
# RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours
# RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
Summary
In the past two days, several critical vulnerabilities affecting key Web3 infrastructure components have been disclosed. The primary sources are GitHub advisories detailing multiple security flaws in Git-related tools (GitHub Desktop, Git Credential Manager, Git LFS) that could lead to unauthorized credential leakage and privilege escalation. Additionally, CISA has added newly exploited vulnerabilities to its catalog, highlighting ongoing threats across various protocols. These disclosures underscore the importance of prompt patching and responsible disclosure practices within Web3 development communities.
Key Developments
- CVE-2025-23040 (CVSS score: 6.6) – Maliciously crafted remote URLs could lead to credential leaks in GitHub Desktop. GitHub Desktop Vulnerability Risks Credential Leaks via Malicious...
- CVE-2024-50338 (CVSS score: 7.4) – Carriage-return character in remote URL allows the malicious repository to leak credentials in Git Credential Manager. GitHub Desktop Vulnerability Risks Credential Leaks via Malicious...
- CVE-2024-53263 (CVSS score: 8.5) – Git LFS permits retrieval of credentials via crafted HTTP URLs. GitHub Desktop Vulnerability Risks Credential Leaks via Malicious...
- CVE-2024-53858 (CVSS score: 6.5) – Recursive repository cloning in GitHub CLI can leak authentication tokens to non-GitHub submodule hosts. GitHub Desktop Vulnerability Risks Credential Leaks via Malicious...
- CVE-2024-52006 (CVSS score: 2.1) – Carriage return smuggling in GitHub Desktop allows maliciously crafted URLs to leak credentials to attacker-controlled hosts. GitHub Desktop Vulnerability Risks Credential Leaks via Malicious...
- CVE-2024-50349 (CVSS score: 2.1) – Crafted URLs containing escape sequences could trick users into providing credentials to arbitrary sites. GitHub Desktop Vulnerability Risks Credential Leaks via Malicious...
- CISA Catalog Update – Added one known exploited vulnerability on September 11, 2026; added three known exploited vulnerabilities on September 10, 2026; and two known exploited vulnerabilities on September 9, 2026. CISA Adds Known Exploited Vulnerabilities to Catalog