{"id":"GHSA-5fqc-mrg8-w798","title":"Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence","summary":"Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence","severity":"high","cvss":8.6,"cwe":["CWE-22","CWE-59"],"vendor":"dulwich","product":"dulwich","ecosystem":"pip","affected":["dulwich >= 0.23.1, <= 1.2.7"],"patched":["dulwich 1.2.8"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T18:53:05Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5fqc-mrg8-w798","references":[{"url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-5fqc-mrg8-w798"},{"url":"https://github.com/jelmer/dulwich/commit/9571ac60b851fce228dae7ededb380c6ce9b3fb8"},{"url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.8"},{"url":"https://github.com/advisories/GHSA-5fqc-mrg8-w798"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-02T22:33:09.856Z","slug":"GHSA-5fqc-mrg8-w798","body":"## Overview\n\n## Summary\n\nDulwich's `filter_branch.py` `CommitFilter._apply_index_filter()` is vulnerable to symlink directory traversal. When processing commit history, materialized tree entries (including symlinks) persist in the working directory between commits, allowing a symlink from an ancestor commit to redirect file writes from a descendant commit to arbitrary filesystem locations.\n\n## Root Cause\n\n`_apply_index_filter()` at `dulwich/filter_branch.py:212` calls `build_index_from_tree(\".\", tmp_index_path, ...)` which materializes all tree entries to the current working directory. The `finally` block (line 229-230) only cleans up the temporary index file (`os.unlink(tmp_index_path)`) — NOT the filesystem files written to CWD. When `process_commit()` processes parents recursively first (line 260), files materialized from ancestor commits persist and affect processing of descendant commits.\n\nOn dulwich 1.2.7, `build_file_from_blob()` has no symlink protection, and `validate_path_element` only validates name patterns, not filesystem state.\n\n## Impact\n\nAn attacker can craft a malicious repository where running `filter_branch` with an index filter writes attacker-controlled content to arbitrary filesystem locations via symlink traversal. This achieves RCE if the write targets `.git/hooks/`.\n\n## Attack Scenario\n\n1. Attacker creates a repository where commit history (linearized) has:\n   - Ancestor commit: tree entry `evil` (mode 120000, symlink → `/target_dir`)\n   - Descendant commit: tree entry `evil/payload` (mode 100644, attacker content)\n2. Victim clones repository and runs `filter_branch` with an index filter\n3. `process_commit()` processes ancestor first → materializes `evil` as symlink to `/target_dir` in CWD\n4. CWD is NOT cleaned between commits\n5. Processing descendant: `os.path.exists(\"./evil\")` → True (symlink exists). `build_file_from_blob(blob, mode, \"./evil/payload\")` → `open(\"./evil/payload\", \"wb\")` follows intermediate symlink → writes to `/target_dir/payload`\n\n## Suggested Fix\n\nClean the CWD between commit iterations in `_apply_index_filter()`, or verify that no intermediate path components are symlinks before writing files.\n\nReported by **zx (Jace)**\n\n## Affected packages\n\n- `dulwich >= 0.23.1, <= 1.2.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `dulwich 1.2.8`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}