PatchSiren

isomorphic-git CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH isomorphic-git CVE published 2026-09-10

CVE-2026-89011

CVE-2026-89011 is a prototype pollution vulnerability in the getRemoteInfo function of isomorphic-git before version 1.42.0. This vulnerability allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. As a result, attackers controlling a Git server can reroute all subsequent network operations through a [truncated]