cbcvebase.
CVE-2025-27613
published 2025-07-10

CVE-2025-27613: Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments…

PriorityP414low3.6CVSS 3.1
AVLACLPRNUIRSCCNILAN
EPSS
0.29%
20.9th percentile
Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs gitk without additional command arguments, files for which the user has write permission can be created and truncated. The option Support per-file encoding must have been enabled before in Gitk's Preferences. This option is disabled by default. The same happens when Show origin of this line is used in the main window (regardless of whether Support per-file encoding is enabled or not). This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiangit< git 1:2.39.5-0+deb12u3 (bookworm)git 1:2.39.5-0+deb12u3 (bookworm)
gitgit>= 0 < 1:2.30.2-1+deb11u51:2.30.2-1+deb11u5
gitgit>= 0 < 1:2.39.5-0+deb12u31:2.39.5-0+deb12u3
gitgit>= 0 < 1:2.47.3-0+deb13u11:2.47.3-0+deb13u1
gitgit>= 0 < 1:2.50.1-0.11:2.50.1-0.1
gitgit>= 0 < 1:2.34.1-1ubuntu1.141:2.34.1-1ubuntu1.14
gitgit>= 0 < 1:2.34.1-1ubuntu1.151:2.34.1-1ubuntu1.15
gitgit>= 0 < 1:2.34.1-1ubuntu1.131:2.34.1-1ubuntu1.13
gitgit>= 0 < 1:2.43.0-1ubuntu7.31:2.43.0-1ubuntu7.3
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm101:2.7.4-0ubuntu1.10+esm10
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm111:2.7.4-0ubuntu1.10+esm11
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm91:2.7.4-0ubuntu1.10+esm9
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm31:2.17.1-1ubuntu0.18+esm3
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm41:2.17.1-1ubuntu0.18+esm4
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm21:2.17.1-1ubuntu0.18+esm2
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm21:2.25.1-1ubuntu3.14+esm2
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm31:2.25.1-1ubuntu3.14+esm3
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm11:2.25.1-1ubuntu3.14+esm1
j6tgitk
j6tgitk
j6tgitk
j6tgitk
j6tgitk
j6tgitk
j6tgitk

CVSS provenance

nvdv3.13.6LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
osv3.6LOW
vendor_debian3.6LOW
vendor_msrc3.6LOW
vendor_redhat3.6LOW
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.