Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52726

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, dulwich.porcelain.submodule_update, and by extension porcelain.clone(..., recurse_submodules=True), materializes attacker-controlled submodule paths from a crafted upstream repository without path validation. A malicious .gitmodules plus a matching tree gitlink whose path is .git/hooks (or any other directory inside the parent repository's .git directory) causes the attacker's submodule tree contents to be written directly into the victim's .git/hooks/ directory, preserving executable mode bits. The dropped executables are then run by any subsequent git or dulwich command that invokes the matching hook, resulting in arbitrary code execution. This is the dulwich equivalent of the upstream Git fixes for CVE-2024-32002 / CVE-2024-32004, which were never propagated into dulwich's separately implemented submodule porcelain. Version 1.2.5 patches the issue.

A flaw was found in Dulwich, a pure-Python implementation of Git file formats and protocols. This vulnerability allows a remote attacker to achieve arbitrary code execution by crafting a malicious Git submodule. When a user clones or updates a repository with such a submodule, the attacker-controlled content is written into the victim's Git hooks directory. Subsequent Git or Dulwich commands can then execute these malicious files, leading to system compromise.

Отчет

Red Hat product security classifies this bug as Important as this bug can be triggered by the victim merely by cloning a maliciours repository. The attacker is however unable to trigger any executable without subsequent actions by the victim. Users should pay attention to any binaries that are cloned over as this is not normal and not clone untrusted repositories. There is no loss of integrity and confidentiality loss can be minimal depending on the due diligence executed by the user so the CVSS score is rated lower even though this bug is classified as Important.

Меры по смягчению последствий

To mitigate this issue, users should avoid cloning or updating Git repositories that contain submodules from untrusted or unverified sources. When interacting with repositories, especially those with submodules, ensure the source is trusted to prevent the execution of arbitrary code via crafted Git hooks. If possible, review the .gitmodules file and the submodule's content before performing recursive submodule operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/eda-controller-rhel9Not affected
Red Hat Enterprise Linux 8resource-agentsAffected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-autogluon-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-router-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2487769dulwich: Dulwich: Arbitrary code execution via crafted Git submodules

EPSS

Процентиль: 37%
0.00448
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension `porcelain.clone(..., recurse_submodules=True)`, materializes attacker-controlled submodule paths from a crafted upstream repository without path validation. A malicious `.gitmodules` plus a matching tree gitlink whose `path` is `.git/hooks` (or any other directory inside the parent repository's `.git` directory) causes the attacker's submodule tree contents to be written directly into the victim's `.git/hooks/` directory, preserving executable mode bits. The dropped executables are then run by any subsequent `git` or `dulwich` command that invokes the matching hook, resulting in arbitrary code execution. This is the dulwich equivalent of the upstream Git fixes for CVE-2024-32002 / CVE-2024-32004, which were never propagated into dulwich's separately implemented submodule porcelain. Version 1.2.5 ...

CVSS3: 7.5
nvd
около 2 месяцев назад

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension `porcelain.clone(..., recurse_submodules=True)`, materializes attacker-controlled submodule paths from a crafted upstream repository without path validation. A malicious `.gitmodules` plus a matching tree gitlink whose `path` is `.git/hooks` (or any other directory inside the parent repository's `.git` directory) causes the attacker's submodule tree contents to be written directly into the victim's `.git/hooks/` directory, preserving executable mode bits. The dropped executables are then run by any subsequent `git` or `dulwich` command that invokes the matching hook, resulting in arbitrary code execution. This is the dulwich equivalent of the upstream Git fixes for CVE-2024-32002 / CVE-2024-32004, which were never propagated into dulwich's separately implemented submodule porcelain. Version 1.2.5 pat

CVSS3: 7.5
debian
около 2 месяцев назад

Dulwich is a pure-Python implementation of the Git file formats and pr ...

CVSS3: 7.5
github
около 1 месяца назад

Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость библиотеки Python для работы с репозиториями Git Dulwich, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 37%
0.00448
Низкий

5.4 Medium

CVSS3