Arbitrary File Write in Dulwich via Malicious Git Tree Paths
The Dulwich Git library for Python fails to validate DOS drive letter prefixes on Windows, allowing a malicious Git repository to write files to arbitrary locations outside the designated worktree.
What's new
Dulwich, a pure-Python implementation of the Git protocol, contains a critical path traversal vulnerability (versions < 1.2.9) when executing checkout operations on Windows. The library implements security checks in validate_path_element_ntfs and _tree_to_fs_path to block malicious path patterns like Alternate Data Streams (ADS) and reserved device names. However, these functions fail to identify or sanitize DOS drive letter prefixes (e.g., 'C:').
An attacker can craft a malicious Git repository containing a tree entry with a drive letter prefix. When a victim clones or checks out this repository on a Windows system, the library uses os.path.join incorrectly, causing the application to interpret the drive letter as an absolute path. This results in the target file being written to a location specified by the attacker, effectively discarding the intended worktree directory. This vulnerability provides a reliable primitive for Arbitrary File Write, which an attacker can weaponize to achieve Remote Code Execution (RCE) by targeting sensitive startup folders, user configuration files, or SSH keys.
Attack Chain
- Attacker crafts a malicious Git repository on a Linux system containing a tree structure with a directory named 'C:'.
- Attacker populates the 'C:' directory with a malicious payload, such as a startup shortcut or a modified '.gitconfig' file.
- Attacker pushes the repository to a public Git hosting platform or lures a victim to clone the repository.
- Victim executes a
dulwichclone or checkout command on a Windows machine. - Dulwich processes the malicious tree entry 'C:' and incorrectly joins it with the target worktree path.
- Python's
os.path.joinon Windows recognizes the drive letter prefix and treats the path as absolute, bypassing the target directory constraint. - Dulwich writes the attacker-supplied payload to an arbitrary location on the victim's filesystem.
- Upon file execution or system interaction with the malicious file, the attacker gains code execution or persistence on the victim's host.
Impact
Successful exploitation results in arbitrary file write capabilities on Windows systems. This impact is severe for developers or CI/CD runners (e.g., GitHub Actions) using Dulwich, as it allows attackers to gain code execution by overwriting configuration files like C:\Users\<user>\.gitconfig or placing malicious binaries in C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\. CI/CD pipelines are particularly vulnerable, as automated clones of malicious PRs can result in secret exfiltration and immediate host compromise.
Recommendation
- Upgrade the
dulwichlibrary to version 1.2.9 or later immediately to incorporate necessary path validation logic. - Implement monitoring for process creation events where
python.exeorgit.execlones or checks out repositories to unconventional target paths on Windows. - Restrict write permissions on sensitive system directories such as the Windows Startup folder and user SSH directories to prevent unauthorized modifications by legitimate application processes.
- Audit CI/CD runner environments for the presence of Dulwich and ensure runners are configured to use hardened Git clients or updated versions of the library.
Immediate actions
Upgrade dulwich to version 1.2.9 or later
Mitigations
Upgrade dulwich to 1.2.9
dulwich < 1.2.9