CVE-2025-46334
published 2025-07-10CVE-2025-46334: Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter…
PriorityP343high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
0.26%
17.7th percentile
Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory. The mentioned programs are invoked when the user selects Git Bash or Browse Files from the menu. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | git | — | — |
| git | git | >= 0 < 2.43.7-r0 | 2.43.7-r0 |
| git | git | >= 0 < 2.45.4-r0 | 2.45.4-r0 |
| git | git | >= 0 < 2.47.3-r0 | 2.47.3-r0 |
| git | git | >= 0 < 2.49.1-r0 | 2.49.1-r0 |
| git | git | >= 0 < 2.50.1-r0 | 2.50.1-r0 |
| j6t | git-gui | < 2.43.7 | 2.43.7 |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| msrc | microsoft_visual_studio_2017_version_15.9 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.10 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.14 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
osv8.6HIGH
vendor_debian8.6LOW
vendor_msrc8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
GitHub: CVE-2025-46334 Git Malicious Shell Vulnerability
vendor_msrc·2025-07-08·CVSS 8.6
CVE-2025-46334 [HIGH] GitHub: CVE-2025-46334 Git Malicious Shell Vulnerability
GitHub: CVE-2025-46334 Git Malicious Shell Vulnerability
Description: CVE-2025-46334 is regarding a vulnerability in Git GUI (Windows only) where a malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. On Windows, path lookup can find such executables in the worktree. These programs are invoked when the user selects "Git Bash" or "Browse Files" from the menu. GitHub created this CVE on their behalf. The documented Visual Studio updates incorporate updates in GitK which address this vulnerability.
Please see CVE-2025-46334 for more information.
Visual Studio: Visual Studio
GitHub: GitHub
Customer Action Required: Yes
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8
Referen
Debian
CVE-2025-46334: git - Git GUI allows you to use the Git source control management tools via a GUI. A m...
vendor_debian·2025·CVSS 8.6
CVE-2025-46334 [HIGH] CVE-2025-46334: git - Git GUI allows you to use the Git source control management tools via a GUI. A m...
Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory. The mentioned programs are invoked when the user selects Git Bash or Browse Files from the menu. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
CVE-2025-46334: Git GUI allows you to use the Git source control management tools via a GUI
osv·2025-07-10·CVSS 8.6
CVE-2025-46334 [HIGH] CVE-2025-46334: Git GUI allows you to use the Git source control management tools via a GUI
Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory. The mentioned programs are invoked when the user selects Git Bash or Browse Files from the menu. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-10
Published