cbcvebase.
CVE-2025-27614
published 2025-07-10

CVE-2025-27614: Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who…

PriorityP344high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
0.31%
23.5th percentile
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiangit< git 1:2.50.1-0.1 (forky)git 1:2.50.1-0.1 (forky)
gitgit>= 0 < 1:2.47.3-0+deb13u11:2.47.3-0+deb13u1
gitgit>= 0 < 1:2.50.1-0.11:2.50.1-0.1
gitgit>= 0 < 1:2.34.1-1ubuntu1.141:2.34.1-1ubuntu1.14
gitgit>= 0 < 1:2.34.1-1ubuntu1.151:2.34.1-1ubuntu1.15
gitgit>= 0 < 1:2.34.1-1ubuntu1.131:2.34.1-1ubuntu1.13
gitgit>= 0 < 1:2.43.0-1ubuntu7.31:2.43.0-1ubuntu7.3
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm101:2.7.4-0ubuntu1.10+esm10
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm111:2.7.4-0ubuntu1.10+esm11
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm91:2.7.4-0ubuntu1.10+esm9
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm31:2.17.1-1ubuntu0.18+esm3
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm41:2.17.1-1ubuntu0.18+esm4
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm21:2.17.1-1ubuntu0.18+esm2
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm21:2.25.1-1ubuntu3.14+esm2
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm31:2.25.1-1ubuntu3.14+esm3
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm11:2.25.1-1ubuntu3.14+esm1
j6tgitk
j6tgitk
j6tgitk
j6tgitk
j6tgitk
j6tgitk
j6tgitk
j6tgitk
msrcmicrosoft_visual_studio_2017_version_15.9

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv8.6HIGH
vendor_debian8.6LOW
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.