{"thread":{"id":"64738","subject":"question about affected version of CVE-2025-48385","startedAt":"2026-01-07T05:36:28Z","lastAt":"2026-01-07T05:36:28Z","messageCount":1,"participants":["Jinfeng Wang"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"533182","messageId":"44c4e575-bf5c-45a4-8035-ad4007e95fe3@windriver.com","threadId":"64738","inReplyTo":null,"subject":"question about affected version of CVE-2025-48385","fromName":"Jinfeng Wang","fromEmail":"jinfeng.wang.cn@windriver.com","sentAt":"2026-01-07T05:36:20Z","receivedAt":"2026-01-07T05:36:28Z","isPatch":false,"sender":{"key":"jinfeng.wang.cn@windriver.com","avatar":null},"body":"Hi all,\n\nFor this CVE https://nvd.nist.gov/vuln/detail/CVE-2025-48385,\n\nAffected vesion listed in \nhttps://github.com/git/git/security/advisories/GHSA-m98c-vgpc-9655:\nAffected versions\nv2.50.0, v2.49.0, v2.48.0-v2.48.1, v2.47.0–v2.47.2, v2.46.0–v2.46.3, \nv2.45.0-v2.45.3, v2.44.0–v2.44.3, v2.43.6 and prior\n\nBut I see the fix is for bundle-uri:\n\ngit log --grep=\"CVE-2025-48385\"\ncommit d2bc61fcabd6cfa582d286bed1ce20d5d7c58d52\nMerge: d61cfed2c2 35cb1bb0b9\nAuthor: Taylor Blau <me@ttaylorr.com>\nDate:   Wed May 28 12:53:52 2025 -0400\n\n     Merge branch 'ps/bundle-uri-arbitrary-writes' into maint-2.43\n\n     This merges in the fix for CVE-2025-48385.\n\n     * ps/bundle-uri-arbitrary-writes:\n       bundle-uri: fix arbitrary file writes via parameter injection\n\nBut bundle-uri is added in v2.38.0, so the version before v2.38.0 is not \naffected. Is that right?\n\n\nRegards,\n\nJinfeng\n\n"}]}