CPE
high
advisory
Path Traversal in GitPython via Malicious Submodule Names
1 TTP 1 CVEGitPython fails to validate submodule names defined in .gitmodules files, allowing attackers to perform path traversal and create arbitrary Git repositories outside the intended working tree during submodule initialization.
GitPython +1
remote-code-execution
input-validation
python
1t
1c
high
advisory
Dulwich Arbitrary File Write Vulnerability on Windows (CVE-2026-42305)
2 rules 2 CVEsDulwich versions before 1.2.5 are vulnerable to an arbitrary file write leading to remote code execution on Windows systems when cloning or checking out a malicious Git repository due to improper path validation, as tracked by CVE-2026-42305.
dulwich
arbitrary-file-write
remote-code-execution
git
2r
2c