<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Dulwich (&gt;= 0.23.1, &lt;= 1.2.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dulwich--0.23.1--1.2.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 20:23:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dulwich--0.23.1--1.2.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Write in Dulwich via Malicious Git Tree Paths</title><link>https://feed.craftedsignal.io/briefs/2026-10-dulwich-path-traversal/</link><pubDate>Fri, 02 Oct 2026 20:23:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-dulwich-path-traversal/</guid><description>The Dulwich Git library for Python fails to validate DOS drive letter prefixes on Windows, allowing a malicious Git repository to write files to arbitrary locations outside the designated worktree.</description><content:encoded><![CDATA[<p>Dulwich, a pure-Python implementation of the Git protocol, contains a critical path traversal vulnerability (versions &lt; 1.2.9) when executing checkout operations on Windows. The library implements security checks in <code>validate_path_element_ntfs</code> and <code>_tree_to_fs_path</code> to block malicious path patterns like Alternate Data Streams (ADS) and reserved device names. However, these functions fail to identify or sanitize DOS drive letter prefixes (e.g., 'C:').</p>
<p>An attacker can craft a malicious Git repository containing a tree entry with a drive letter prefix. When a victim clones or checks out this repository on a Windows system, the library uses <code>os.path.join</code> incorrectly, causing the application to interpret the drive letter as an absolute path. This results in the target file being written to a location specified by the attacker, effectively discarding the intended worktree directory. This vulnerability provides a reliable primitive for Arbitrary File Write, which an attacker can weaponize to achieve Remote Code Execution (RCE) by targeting sensitive startup folders, user configuration files, or SSH keys.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious Git repository on a Linux system containing a tree structure with a directory named 'C:'.</li>
<li>Attacker populates the 'C:' directory with a malicious payload, such as a startup shortcut or a modified '.gitconfig' file.</li>
<li>Attacker pushes the repository to a public Git hosting platform or lures a victim to clone the repository.</li>
<li>Victim executes a <code>dulwich</code> clone or checkout command on a Windows machine.</li>
<li>Dulwich processes the malicious tree entry 'C:' and incorrectly joins it with the target worktree path.</li>
<li>Python's <code>os.path.join</code> on Windows recognizes the drive letter prefix and treats the path as absolute, bypassing the target directory constraint.</li>
<li>Dulwich writes the attacker-supplied payload to an arbitrary location on the victim's filesystem.</li>
<li>Upon file execution or system interaction with the malicious file, the attacker gains code execution or persistence on the victim's host.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary file write capabilities on Windows systems. This impact is severe for developers or CI/CD runners (e.g., GitHub Actions) using Dulwich, as it allows attackers to gain code execution by overwriting configuration files like <code>C:\Users\&lt;user&gt;\.gitconfig</code> or placing malicious binaries in <code>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\</code>. CI/CD pipelines are particularly vulnerable, as automated clones of malicious PRs can result in secret exfiltration and immediate host compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the <code>dulwich</code> library to version 1.2.9 or later immediately to incorporate necessary path validation logic.</li>
<li>Implement monitoring for process creation events where <code>python.exe</code> or <code>git.exe</code> clones or checks out repositories to unconventional target paths on Windows.</li>
<li>Restrict write permissions on sensitive system directories such as the Windows Startup folder and user SSH directories to prevent unauthorized modifications by legitimate application processes.</li>
<li>Audit CI/CD runner environments for the presence of Dulwich and ensure runners are configured to use hardened Git clients or updated versions of the library.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>git</category><category>remote-code-execution</category><category>python</category></item></channel></rss>