Loading
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
Use CWE-116, Git-Scm vendor hub and Git product page to widen CVE-2014-9938 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-48384, CVE-2022-41903 and CVE-2022-23521 for nearby disclosures in the same product family.