Echo: git: security update to 1:2.50.1-0.1

high Tenable Self-Hosted Container Security Plugin ID 460178

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such
a way that with some social engineering a user who has cloned the repository can be tricked into running
any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename,
where filename has a particular structure. The script is run with the privileges of the user. This
vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.
(CVE-2025-27614)

Solution

Update the git library and its related packages to version 1:2.50.1-0.1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-27614

Plugin Details

Severity: High

ID: 460178

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/5/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.19

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-27614

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/29/2026

Vulnerability Publication Date: 1/29/2026

Reference Information

CVE: CVE-2025-27614