CVE-2025-27614
published 2025-07-10CVE-2025-27614: Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who…
PriorityP344high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
0.31%
23.5th percentile
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | git | < git 1:2.50.1-0.1 (forky) | git 1:2.50.1-0.1 (forky) |
| git | git | >= 0 < 1:2.47.3-0+deb13u1 | 1:2.47.3-0+deb13u1 |
| git | git | >= 0 < 1:2.50.1-0.1 | 1:2.50.1-0.1 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.14 | 1:2.34.1-1ubuntu1.14 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.15 | 1:2.34.1-1ubuntu1.15 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.13 | 1:2.34.1-1ubuntu1.13 |
| git | git | >= 0 < 1:2.43.0-1ubuntu7.3 | 1:2.43.0-1ubuntu7.3 |
| git | git | >= 0 < 1:2.7.4-0ubuntu1.10+esm10 | 1:2.7.4-0ubuntu1.10+esm10 |
| git | git | >= 0 < 1:2.7.4-0ubuntu1.10+esm11 | 1:2.7.4-0ubuntu1.10+esm11 |
| git | git | >= 0 < 1:2.7.4-0ubuntu1.10+esm9 | 1:2.7.4-0ubuntu1.10+esm9 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.18+esm3 | 1:2.17.1-1ubuntu0.18+esm3 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.18+esm4 | 1:2.17.1-1ubuntu0.18+esm4 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.18+esm2 | 1:2.17.1-1ubuntu0.18+esm2 |
| git | git | >= 0 < 1:2.25.1-1ubuntu3.14+esm2 | 1:2.25.1-1ubuntu3.14+esm2 |
| git | git | >= 0 < 1:2.25.1-1ubuntu3.14+esm3 | 1:2.25.1-1ubuntu3.14+esm3 |
| git | git | >= 0 < 1:2.25.1-1ubuntu3.14+esm1 | 1:2.25.1-1ubuntu3.14+esm1 |
| j6t | gitk | — | — |
| j6t | gitk | — | — |
| j6t | gitk | — | — |
| j6t | gitk | — | — |
| j6t | gitk | — | — |
| j6t | gitk | — | — |
| j6t | gitk | — | — |
| j6t | gitk | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv8.6HIGH
vendor_debian8.6LOW
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Git regression
vendor_ubuntu·2025-07-10·CVSS 3.6
CVE-2025-27613 [LOW] Git regression
Title: Git regression
Summary: USN-7626-1 introduced a regression in Git
USN-7626-1 fixed vulnerabilities in Git. The updates for CVE-2025-27613
and CVE-2025-46835 caused Gitk and Git GUI to not work properly on Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and
were disabled in USN-7626-2. The problematic updates for the
aforementioned CVEs have now been corrected and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If
Ubuntu
Git regression
vendor_ubuntu·2025-07-09·CVSS 3.6
CVE-2025-27613 [LOW] Git regression
Title: Git regression
Summary: USN-7626-1 introduced a regression in Git.
USN-7626-1 fixed vulnerabilities in Git. The update introduced a regression
in gitk and git-gui. This update reverts the corresponding fixes for
CVE-2025-27613 and CVE-2025-46835 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue on
Ubuntu
Git vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 3.6
CVE-2025-46835 [LOW] Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and
Ubuntu 25.04. (CVE-2025-27614)
Johannes Sixt discovered that Git incorrectly managed file modification
constraints with Git GUI. If a user were tricked into editing a file in a
malicious Git repository, an attacker could p
Red Hat
gitk: git script execution flaw
vendor_redhat·2025-07-08·CVSS 8.6
CVE-2025-27614 [HIGH] gitk: git script execution flaw
gitk: git script execution flaw
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.
There's a vulnerability in gitk where an user can be tricked to run malicious scripts supplied by the attacker when running gitk filename command. When successfully exploited this vulnerability may result in arbitrary code execution.
Statement: The Red Hat Pro
Microsoft
GitHub: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability
vendor_msrc·2025-07-08·CVSS 8.6
CVE-2025-27614 [HIGH] GitHub: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability
GitHub: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability
Description: CVE-2025-27614 is regarding a vulnerability in Gitk where a Git repository can be crafted in such a way that a user who has cloned the repository can be tricked into running any script supplied by the attacker by invoking gitk filename, where filename has a particular structure. GitHub created this CVE on their behalf. The documented Visual Studio updates incorporate updates in GitK which address this vulnerability.
Please see CVE-2025-27614 for more information.
Visual Studio: Visual Studio
GitHub: GitHub
Customer Action Required: Yes
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8
Reference: https://learn.microsoft.com/en-us/visualstudio/rel
Debian
CVE-2025-27614: git - Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git reposito...
vendor_debian·2025·CVSS 8.6
CVE-2025-27614 [HIGH] CVE-2025-27614: git - Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git reposito...
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:2.50.1-0.1)
sid: resolved (fixed in 1:2.50.1-0.1)
trixie: resolved (fixed in 1:2.47.3-0+deb13u1)
OSV
CVE-2025-27614: Gitk is a Tcl/Tk based Git history browser
osv·2025-07-10·CVSS 8.6
CVE-2025-27614 [HIGH] CVE-2025-27614: Gitk is a Tcl/Tk based Git history browser
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.
OSV
git regression
osv·2025-07-10·CVSS 3.6
CVE-2025-27613 [LOW] git regression
git regression
USN-7626-1 fixed vulnerabilities in Git. The updates for CVE-2025-27613
and CVE-2025-46835 caused Gitk and Git GUI to not work properly on Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and
were disabled in USN-7626-2. The problematic updates for the
aforementioned CVEs have now been corrected and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repositor
OSV
git regression
osv·2025-07-09·CVSS 3.6
CVE-2025-27613 [LOW] git regression
git regression
USN-7626-1 fixed vulnerabilities in Git. The update introduced a regression
in gitk and git-gui. This update reverts the corresponding fixes for
CVE-2025-27613 and CVE-2025-46835 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and
Ubuntu 25.04
OSV
git vulnerabilities
osv·2025-07-08·CVSS 3.6
CVE-2025-27613 [LOW] git vulnerabilities
git vulnerabilities
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and
Ubuntu 25.04. (CVE-2025-27614)
Johannes Sixt discovered that Git incorrectly managed file modification
constraints with Git GUI. If a user were tricked into editing a file in a
malicious Git repository, an attacker could possibly use this issue to
create or write to arbitrary files
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-27614 cgit: git script execution flaw [fedora-42]
bugzilla·2026-01-15·CVSS 8.6
CVE-2025-27614 [HIGH] CVE-2025-27614 cgit: git script execution flaw [fedora-42]
CVE-2025-27614 cgit: git script execution flaw [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'version'
to a later Fedora
Bugzilla
CVE-2025-27614 gitk: git script execution flaw
bugzilla·2025-07-09·CVSS 8.6
CVE-2025-27614 [HIGH] CVE-2025-27614 gitk: git script execution flaw
CVE-2025-27614 gitk: git script execution flaw
A Git repository can be crafted in such a way that a user who has cloned the repository can be tricked into running any script supplied by the attacker by invoking `gitk filename`, where `filename` has a particular structure.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:11462 https://access.redhat.com/errata/RHSA-2025:11462
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:11533 https://access.redhat.com/errata/RHSA-2025:11533
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:11534 https://access.redhat.com/errata/RHSA-2025:11534
---
This issue has been addresse
2025-07-10
Published