{"id":"GHSA-cm62-gvxx-vmxx","title":"Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks","summary":"Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks","severity":"high","cvss":8.6,"cwe":["CWE-22","CWE-59"],"vendor":"dulwich","product":"dulwich","ecosystem":"pip","affected":["dulwich >= 0.22.5, <= 1.2.7"],"patched":["dulwich 1.2.8"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T18:52:55Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-cm62-gvxx-vmxx","references":[{"url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-cm62-gvxx-vmxx"},{"url":"https://github.com/jelmer/dulwich/commit/40a542cb02f9ac39a9eeac1193472903098698f9"},{"url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.8"},{"url":"https://github.com/advisories/GHSA-cm62-gvxx-vmxx"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-02T22:33:09.856Z","slug":"GHSA-cm62-gvxx-vmxx","body":"## Overview\n\n## Summary\n\nDulwich's `stash.py:pop()` function is vulnerable to symlink directory traversal, allowing an attacker to write arbitrary files outside the repository worktree when a victim pops a stash in a malicious repository.\n\n## Root Cause\n\nThe `pop()` function at `dulwich/stash.py:236` uses `os.path.exists(parent_dir)` to check if a parent directory exists before writing stashed files. `os.path.exists()` follows symlinks, so when an intermediate directory in the path is a symlink pointing outside the worktree (e.g., `link → ../../.git/hooks`), the check passes and subsequent file writes resolve through the symlink.\n\nThe `validate_path()` function (line 228) only validates path component names against `INVALID_DOTNAMES` — it performs zero filesystem symlink detection. On dulwich 1.2.7 (latest release), `build_file_from_blob()` has no symlink protection whatsoever.\n\n## Impact\n\nAn attacker can craft a malicious repository that, when a victim clones it and performs a stash pop operation, writes attacker-controlled content to arbitrary filesystem locations. Writing to `.git/hooks/post-checkout` achieves Remote Code Execution on the victim's machine on the next git checkout operation.\n\n## Attack Scenario\n\n1. Attacker creates a repository with branch `main` containing `link` (symlink → `../../.git/hooks`) and branch `feature` containing `link/post-checkout` (executable payload)\n2. Victim clones the repository (landing on `main` — symlink `link` exists in worktree)\n3. Victim checks out `feature`, makes changes, runs `stash.push()`\n4. Victim checks out `main` (restoring the `link` symlink)\n5. Victim runs `stash.pop(0)` — stash contains `link/post-checkout`\n6. `os.path.exists(\"link\")` returns True (symlink to existing directory), `os.makedirs` skipped\n7. `build_file_from_blob(blob, mode, \"link/post-checkout\")` → `open(\"link/post-checkout\", \"wb\")` follows the intermediate symlink → payload written to `.git/hooks/post-checkout`\n8. Next checkout operation triggers the hook → RCE\n\n## Suggested Fix\n\nBefore writing any file, verify that no component of the target path resolves through a symlink outside the worktree. Use `os.path.realpath(parent_dir)` and confirm it stays within the repository root. Alternatively, use `os.open()` with `O_NOFOLLOW` on each path component.\n\nReported by **zx (Jace)**\n\n## Affected packages\n\n- `dulwich >= 0.22.5, <= 1.2.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `dulwich 1.2.8`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}