---
id: GHSA-5fqc-mrg8-w798
title: >-
  Dulwich: Symlink directory traversal in filter-branch index_filter via
  cross-commit state persistence
summary: >-
  Dulwich: Symlink directory traversal in filter-branch index_filter via
  cross-commit state persistence
severity: high
cvss: 8.6
cwe:
  - CWE-22
  - CWE-59
vendor: dulwich
product: dulwich
ecosystem: pip
affected:
  - 'dulwich >= 0.23.1, <= 1.2.7'
patched:
  - dulwich 1.2.8
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:53:05Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-5fqc-mrg8-w798'
references:
  - url: 'https://github.com/jelmer/dulwich/security/advisories/GHSA-5fqc-mrg8-w798'
  - url: >-
      https://github.com/jelmer/dulwich/commit/9571ac60b851fce228dae7ededb380c6ce9b3fb8
  - url: 'https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.8'
  - url: 'https://github.com/advisories/GHSA-5fqc-mrg8-w798'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-02T22:33:09.856Z'
---

## Overview

## Summary

Dulwich's `filter_branch.py` `CommitFilter._apply_index_filter()` is vulnerable to symlink directory traversal. When processing commit history, materialized tree entries (including symlinks) persist in the working directory between commits, allowing a symlink from an ancestor commit to redirect file writes from a descendant commit to arbitrary filesystem locations.

## Root Cause

`_apply_index_filter()` at `dulwich/filter_branch.py:212` calls `build_index_from_tree(".", tmp_index_path, ...)` which materializes all tree entries to the current working directory. The `finally` block (line 229-230) only cleans up the temporary index file (`os.unlink(tmp_index_path)`) — NOT the filesystem files written to CWD. When `process_commit()` processes parents recursively first (line 260), files materialized from ancestor commits persist and affect processing of descendant commits.

On dulwich 1.2.7, `build_file_from_blob()` has no symlink protection, and `validate_path_element` only validates name patterns, not filesystem state.

## Impact

An attacker can craft a malicious repository where running `filter_branch` with an index filter writes attacker-controlled content to arbitrary filesystem locations via symlink traversal. This achieves RCE if the write targets `.git/hooks/`.

## Attack Scenario

1. Attacker creates a repository where commit history (linearized) has:
   - Ancestor commit: tree entry `evil` (mode 120000, symlink → `/target_dir`)
   - Descendant commit: tree entry `evil/payload` (mode 100644, attacker content)
2. Victim clones repository and runs `filter_branch` with an index filter
3. `process_commit()` processes ancestor first → materializes `evil` as symlink to `/target_dir` in CWD
4. CWD is NOT cleaned between commits
5. Processing descendant: `os.path.exists("./evil")` → True (symlink exists). `build_file_from_blob(blob, mode, "./evil/payload")` → `open("./evil/payload", "wb")` follows intermediate symlink → writes to `/target_dir/payload`

## Suggested Fix

Clean the CWD between commit iterations in `_apply_index_filter()`, or verify that no intermediate path components are symlinks before writing files.

Reported by **zx (Jace)**

## Affected packages

- `dulwich >= 0.23.1, <= 1.2.7`

## Remediation

Upgrade to a patched release:

- `dulwich 1.2.8`
