{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dulwich--1.2.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["dulwich (\u003c 1.2.9)","dulwich (\u003e= 0.24.0, \u003c= 1.2.7)","dulwich (\u003e= 0.23.1, \u003c= 1.2.7)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","git","remote-code-execution","python"],"_cs_type":"advisory","_cs_vendors":["Dulwich"],"content_html":"\u003cp\u003eDulwich, a pure-Python implementation of the Git protocol, contains a critical path traversal vulnerability (versions \u0026lt; 1.2.9) when executing checkout operations on Windows. The library implements security checks in \u003ccode\u003evalidate_path_element_ntfs\u003c/code\u003e and \u003ccode\u003e_tree_to_fs_path\u003c/code\u003e to block malicious path patterns like Alternate Data Streams (ADS) and reserved device names. However, these functions fail to identify or sanitize DOS drive letter prefixes (e.g., 'C:').\u003c/p\u003e\n\u003cp\u003eAn attacker can craft a malicious Git repository containing a tree entry with a drive letter prefix. When a victim clones or checks out this repository on a Windows system, the library uses \u003ccode\u003eos.path.join\u003c/code\u003e incorrectly, causing the application to interpret the drive letter as an absolute path. This results in the target file being written to a location specified by the attacker, effectively discarding the intended worktree directory. This vulnerability provides a reliable primitive for Arbitrary File Write, which an attacker can weaponize to achieve Remote Code Execution (RCE) by targeting sensitive startup folders, user configuration files, or SSH keys.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious Git repository on a Linux system containing a tree structure with a directory named 'C:'.\u003c/li\u003e\n\u003cli\u003eAttacker populates the 'C:' directory with a malicious payload, such as a startup shortcut or a modified '.gitconfig' file.\u003c/li\u003e\n\u003cli\u003eAttacker pushes the repository to a public Git hosting platform or lures a victim to clone the repository.\u003c/li\u003e\n\u003cli\u003eVictim executes a \u003ccode\u003edulwich\u003c/code\u003e clone or checkout command on a Windows machine.\u003c/li\u003e\n\u003cli\u003eDulwich processes the malicious tree entry 'C:' and incorrectly joins it with the target worktree path.\u003c/li\u003e\n\u003cli\u003ePython's \u003ccode\u003eos.path.join\u003c/code\u003e on Windows recognizes the drive letter prefix and treats the path as absolute, bypassing the target directory constraint.\u003c/li\u003e\n\u003cli\u003eDulwich writes the attacker-supplied payload to an arbitrary location on the victim's filesystem.\u003c/li\u003e\n\u003cli\u003eUpon file execution or system interaction with the malicious file, the attacker gains code execution or persistence on the victim's host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary file write capabilities on Windows systems. This impact is severe for developers or CI/CD runners (e.g., GitHub Actions) using Dulwich, as it allows attackers to gain code execution by overwriting configuration files like \u003ccode\u003eC:\\Users\\\u0026lt;user\u0026gt;\\.gitconfig\u003c/code\u003e or placing malicious binaries in \u003ccode\u003eC:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\\u003c/code\u003e. CI/CD pipelines are particularly vulnerable, as automated clones of malicious PRs can result in secret exfiltration and immediate host compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003edulwich\u003c/code\u003e library to version 1.2.9 or later immediately to incorporate necessary path validation logic.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for process creation events where \u003ccode\u003epython.exe\u003c/code\u003e or \u003ccode\u003egit.exe\u003c/code\u003e clones or checks out repositories to unconventional target paths on Windows.\u003c/li\u003e\n\u003cli\u003eRestrict write permissions on sensitive system directories such as the Windows Startup folder and user SSH directories to prevent unauthorized modifications by legitimate application processes.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD runner environments for the presence of Dulwich and ensure runners are configured to use hardened Git clients or updated versions of the library.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T20:23:25Z","date_published":"2026-10-02T20:23:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-dulwich-path-traversal/","summary":"The Dulwich Git library for Python fails to validate DOS drive letter prefixes on Windows, allowing a malicious Git repository to write files to arbitrary locations outside the designated worktree.","title":"Arbitrary File Write in Dulwich via Malicious Git Tree Paths","url":"https://feed.craftedsignal.io/briefs/2026-10-dulwich-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Dulwich (\u003c 1.2.9)","version":"https://jsonfeed.org/version/1.1"}