CVE-2025-66413: Git for Windows NTLM Hash Theft. Check your machines. (opens in new tab)
A vulnerability in Git for Windows prior to version 2.53.0(2) allows an attacker to obtain a user's NTLM hash by tricking them into cloning from a malicious server, potentially leading to brute-force attacks on the user's account name and password. This vulnerability is fixed in version 2.53.0(2) of Git for Windows.
Read the original article