GHSA-8w8g-wq8h-fq33High· 8.6▾ TwilightDulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Dulwich's porcelain.checkout(paths=[...]) code path writes files using raw os.open(file_path, O_WRONLY|O_CREAT|O_TRUNC, mode) followed by f.write(obj.data). This code path does NOT call build_file_from_blob() at all, completely bypassing any symlink protections (including the unreleased d09f8af fix). os.open without O_NOFOLLOW follows symlinks at both the target file and intermediate directories, allowing arbitrary file writes.
At dulwich/porcelain/__init__.py:5661-5675, the checkout(paths=[...]) implementation:
file_path = _checked_worktree_path(r, path)
os.makedirs(os.path.dirname(file_path), exist_ok=True)
flags = os.O_WRONLY | os.O_CREAT | os.O_TRUNC
with os.fdopen(os.open(file_path, flags, mode), "wb") as f:
f.write(obj.data)
_checked_worktree_path() (line 601-631) only performs name validation — checking that the path doesn't start with / or \\ and that components pass INVALID_DOTNAMES checks. It performs zero filesystem symlink detection.
An attacker can craft a malicious repository that, when a victim clones it and runs checkout(paths=[...]), writes attacker-controlled content (with attacker-controlled permissions) to any filesystem location accessible to the user. Writing to .git/hooks/post-checkout achieves RCE on the next git checkout.
trigger as a symlink (mode 120000, content ../../.git/hooks/post-checkout), and tag v1.0 has trigger as an executable file (mode 100755, content #!/bin/sh\nmalicious_payload)trigger → ../../.git/hooks/post-checkout (a symlink)porcelain.checkout(repo, target="v1.0", paths=["trigger"]) to restore a specific file from a tag_checked_worktree_path(r, "trigger") passes — name validation only, no symlink checkos.open("trigger", O_WRONLY|O_CREAT|O_TRUNC, 0o755) follows the symlink → opens .git/hooks/post-checkout for writingf.write(obj.data) writes the malicious payload to the hookReplace the raw os.open path with a call to build_file_from_blob (once that function is hardened against intermediate symlinks), or add explicit symlink detection: resolve the path with os.path.realpath() and verify it stays within the worktree root before opening.
Reported by zx (Jace)
dulwich >= 0.24.0, <= 1.2.7Upgrade to a patched release:
dulwich 1.2.8Connected by shared product, vendor, weakness, or advisory.
GHSA-5fqc-mrg8-w798High· 8.6Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
GHSA-cm62-gvxx-vmxxHigh· 8.6Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
GHSA-35mr-4567-66vgMedium· 6.5Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
GHSA-8mcx-5rqc-vhmfHigh· 8.8Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
CVE-2026-47712Low· 3.3Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
CVE-2026-47734Medium· 5.7Dulwich has unbounded memory allocation in receive-pack from crafted thin packs