HIGH
isomorphic-git
CVE published 2026-09-10
CVE-2026-89011
CVE-2026-89011 is a prototype pollution vulnerability in the getRemoteInfo function of isomorphic-git before version 1.42.0. This vulnerability allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. As a result, attackers controlling a Git server can reroute all subsequent network operations through a [truncated]