This release fixes a major security hole; upgrading is recommended as soon as possible.

Changes:

  • Security fix: A user could perform a directory traversal using a crafted relative path (using .. and a null byte) to read an arbitrary file on the server
  • Allow display of clone/push urls for projects

Release is on the GitPHP page, and bugs can be reported on Mantis.