Unveiling Security Vulnerabilities in Git Large File Storage Protocol
Yuan Chen, Qinying Wang, Yong Yang, Yuanchao Chen, Yuwei Li, Shouling Ji
Abstract
As an extension to the Git version control system that optimizes the handling of large files and binary content, Git Large File Storage (LFS) has been widely adopted by nearly all Git platforms. While Git LFS offers significant improvements in managing large files, it introduces new security implications that remain largely unexplored. This paper presents the first comprehensive security analysis of Git LFS, identifying 11 critical security properties that LFS servers must uphold. Building on our analysis of these property violations, we propose four new attack vectors: Private LFS File Leakage, LFS File Replacement, Quota-based Denial of Service (DoS), and Quota Escape. These attacks exploit weaknesses in practical LFS server implementations and can lead to serious consequences, including unauthorized access to sensitive files, malware injection, denial of service affecting all public repositories, and resource abuse. To evaluate the security of LFS implementations, we develop a semi-automated black-box testing tool and apply it to 14 major Git platforms. We uncover 36 previously unknown vulnerabilities and have responsibly disclosed them to the respective platform maintainers, receiving positive feedback and over $1800 in bug bounty rewards.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext efb235c9-b57b-4c6b-a377-159c2e5a1d65Cited by top-tier papers1
Ask how each one uses itBuilds on6
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code ContributionsHammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt et al.S&P 2022 · 725 citations
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 130 citations
- Cloud Strife: Mitigating the Security Risks of Domain-Validated CertificatesKevin Borgolte, Tobias Fiebig, Shuang Hao, Christopher Kruegel et al.NDSS 2018 · 63 citations
- Helping Users Automatically Find and Manage Sensitive, Expendable Files in Cloud StorageMohammad Taha Khan, Christopher Tran, Shubham Singh, Dimitri Vasilkov et al.USENIX Security 2021 · 16 citations
Related papers
- Continuous Intrusion: Characterizing the Security of Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao et al.S&P 2023
- Windows plays Jenga: Uncovering Design Weaknesses in Windows File System SecurityDong-uk Kim, JunYoung Park, Sanghak Oh, Hyoungshick Kim et al.CCS 2025
- More Haste, Less Speed: Cache Related Security Threats in Continuous Integration ServicesYacong Gu, Lingyun Ying, Huajun Chai, Yingyuan Pu et al.S&P 2024 · 4 citations
- (In)Security of File Uploads in Node.jsHarun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay et al.WWW 2024 · 6 citations
- Unsafe at Any Copy: Name Collisions from Mixing Case SensitivitiesAditya Basu, John Sampson, Zhiyun Qian, Trent JaegerFAST 2023 · 4 citations
