highCVSS 8.6Vulnerability

GHSA-5fqc-mrg8-w798

## Summary Dulwich's `filter_branch.py` `CommitFilter._apply_index_filter()` is vulnerable to symlink directory traversal. When processing commit history, materialized tree entries (including symlinks) persist in the working directory between commits, allowing a symlink from an ancestor commit to redirect file writes from a descendant commit to arbitrary filesystem locations. ## Root Cause `_apply_index_filter()` at `dulwich/filter_branch.py:212` calls `build_index_from_tree(".", tmp_index_path, ...)` which materializes all tree entries to the current working directory. The `finally` block (line 229-230) only cleans up the temporary index file (`os.unlink(tmp_index_path)`) — NOT the filesystem files written to CWD. When `process_commit()` processes parents recursively first (line 260), files materialized from ancestor commits persist and affect processing of descendant commits. On dulwich 1.2.7, `build_file_from_blob()` has no symlink protection, and `validate_path_element` only validates name patterns, not filesystem state. ## Impact An attacker can craft a malicious repository where running `filter_branch` with an index filter writes attacker-controlled content to arbitrary filesystem locations via symlink traversal. This achieves RCE if the write targets `.git/hooks/`. ## Attack Scenario 1. Attacker creates a repository where commit history (linearized) has: - Ancestor commit: tree entry `evil` (mode 120000, symlink → `/target_dir`) - Descendant commit: tree entry `evil/payload` (mode 100644, attacker content) 2. Victim clones repository and runs `filter_branch` with an index filter 3. `process_commit()` processes ancestor first → materializes `evil` as symlink to `/target_dir` in CWD 4. CWD is NOT cleaned between commits 5. Processing descendant: `os.path.exists("./evil")` → True (symlink exists). `build_file_from_blob(blob, mode, "./evil/payload")` → `open("./evil/payload", "wb")` follows intermediate symlink → writes to `/target_dir/payload` ##

Properties

severity
high
summary
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
cvss_score
8.6
retrieved_at
2026-10-02T19:33:52+00:00
ghsa_published
2026-10-02T18:53:05Z
source_url
https://github.com/advisories/GHSA-5fqc-mrg8-w798
ghsa_updated
2026-10-02T18:53:05Z
ghsa_id
GHSA-5fqc-mrg8-w798
last_source
GitHub Advisory Database
cve_id
GHSA-5fqc-mrg8-w798
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-02T19:33:52+00:00
is_ghsa_only
true

Related Entities (5)

VULNERABLE_TO (1)

←[Software]pip/dulwich

AFFECTS (1)

→[Software]pip/dulwich

HAS_WEAKNESS (2)

→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
→[Weakness]Improper Link Resolution Before File Access ('Link Following')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5fqc-mrg8-w798 (CVSS 8.6) — Ninja Signal Threat Intelligence | Ninja Signal