Junglewise Threat Intelligence

CVE-2026-42305: Dulwich arbitrary file write and RCE via NTFS-hostile tree entries

CVE-2026-42305 · Severity: high · CVSS 8.8 · Published 2026-06-10

Technologies: dulwich (PyPI). Vendors: PyPI.

Executive brief

Dulwich is a Python-based tool used to interact with Git repositories. A security flaw allows a malicious repository to write files to unauthorized locations on a user's computer when they download (clone) or update a project on Windows. This can be used to plant malicious scripts that run automatically, potentially giving an attacker full control over the victim's system.

Technical details

A path traversal vulnerability (CWE-22) exists in Dulwich's path-element validator. The validator fails to properly sanitize filenames containing Windows-specific structural characters such as backslashes (\), colons (:), and NTFS 8.3 short-name aliases (e.g., git~1). An attacker can craft a malicious repository with tree entries like '.git\hooks\pre-commit.exe' which, when cloned on Windows, bypasses directory restrictions to plant executable files inside the .git directory or escape the work tree. The risk was compounded by a bug where 'core.protectNTFS' and 'core.protectHFS' configuration settings were ignored due to a naming mismatch in the lookup logic. This issue is fixed in version 1.2.5, which enforces NTFS validation by default on all platforms.

Affected products

  • Jelmer Vernooij Dulwich >=0.10.0, <1.2.5

Timeline

  • 2026-05-28: patched: Version 1.2.5 released
  • 2026-05-28: advisory: GitHub Security Advisory GHSA-897w-fcg9-f6xj published
  • 2026-06-10: disclosed: CVE-2026-42305 published to NVD

References

Related threats