Executive brief
isomorphic-git is a JavaScript library that allows developers to work with Git repositories in the browser and Node.js environments. A directory traversal vulnerability allows attackers to write files outside the intended repository directory by crafting a malicious Git repository with specially crafted file paths. This could lead to unauthorized file creation or modification on the system running the application.
Technical details
isomorphic-git before version 1.8.2 is vulnerable to directory traversal (CWE-22) through malicious file paths embedded in a Git repository structure. The vulnerability occurs in the checkout functionality when parsing Git trees without sufficient validation of file paths, allowing use of path traversal sequences (e.g., "../"). An attacker can craft a malicious repository that, when checked out by a victim application, writes files to arbitrary locations on the filesystem. The fix, merged in PR #1339, introduces an UnsafeFilepathError that is thrown when detecting malicious paths during Git tree parsing. The vulnerability requires the victim to clone or checkout a malicious repository but does not require authentication or user interaction beyond the checkout operation itself.
Affected products
- isomorphic-git isomorphic-git before 1.8.2
Timeline
- 2021-07-30: disclosed
- 2021-09-02: advisory
- 2021-04-12: patched: PR #1339 merged with fix