CVE-2025-46835
published 2025-07-10CVE-2025-46835: Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file…
PriorityP343high8.5CVSS 3.1
AVLACLPRNUIRSCCHIHAL
EPSS
0.30%
21.8th percentile
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | git | < git 1:2.39.5-0+deb12u3 (bookworm) | git 1:2.39.5-0+deb12u3 (bookworm) |
| git | git | >= 0 < 1:2.30.2-1+deb11u5 | 1:2.30.2-1+deb11u5 |
| git | git | >= 0 < 1:2.39.5-0+deb12u3 | 1:2.39.5-0+deb12u3 |
| git | git | >= 0 < 1:2.47.3-0+deb13u1 | 1:2.47.3-0+deb13u1 |
| git | git | >= 0 < 1:2.50.1-0.1 | 1:2.50.1-0.1 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.14 | 1:2.34.1-1ubuntu1.14 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.15 | 1:2.34.1-1ubuntu1.15 |
| git | git | >= 0 < 1:2.34.1-1ubuntu1.13 | 1:2.34.1-1ubuntu1.13 |
| git | git | >= 0 < 1:2.43.0-1ubuntu7.3 | 1:2.43.0-1ubuntu7.3 |
| git | git | >= 0 < 1:2.7.4-0ubuntu1.10+esm10 | 1:2.7.4-0ubuntu1.10+esm10 |
| git | git | >= 0 < 1:2.7.4-0ubuntu1.10+esm11 | 1:2.7.4-0ubuntu1.10+esm11 |
| git | git | >= 0 < 1:2.7.4-0ubuntu1.10+esm9 | 1:2.7.4-0ubuntu1.10+esm9 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.18+esm3 | 1:2.17.1-1ubuntu0.18+esm3 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.18+esm4 | 1:2.17.1-1ubuntu0.18+esm4 |
| git | git | >= 0 < 1:2.17.1-1ubuntu0.18+esm2 | 1:2.17.1-1ubuntu0.18+esm2 |
| git | git | >= 0 < 1:2.25.1-1ubuntu3.14+esm2 | 1:2.25.1-1ubuntu3.14+esm2 |
| git | git | >= 0 < 1:2.25.1-1ubuntu3.14+esm3 | 1:2.25.1-1ubuntu3.14+esm3 |
| git | git | >= 0 < 1:2.25.1-1ubuntu3.14+esm1 | 1:2.25.1-1ubuntu3.14+esm1 |
| j6t | git-gui | < 2.43.7 | 2.43.7 |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
| j6t | git-gui | — | — |
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
osv8.5HIGH
vendor_debian8.5HIGH
vendor_msrc8.5HIGH
vendor_redhat8.5HIGH
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
git: Git GUI can create and overwrite files for which the user has write permission
vendor_redhat·2025-07-10·CVSS 8.5
CVE-2025-46835 [HIGH] CWE-88 git: Git GUI can create and overwrite files for which the user has write permission
git: Git GUI can create and overwrite files for which the user has write permission
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
A vulnerability was found in the git GUI package. When a user clones an untrusted repository and edits a file located in a maliciously named directory, git GUI may end up creating or overwriting arbitrary files for the running user has written permission. This flaw allows an attacker to modify the content of targe
Ubuntu
Git regression
vendor_ubuntu·2025-07-10·CVSS 3.6
CVE-2025-27613 [LOW] Git regression
Title: Git regression
Summary: USN-7626-1 introduced a regression in Git
USN-7626-1 fixed vulnerabilities in Git. The updates for CVE-2025-27613
and CVE-2025-46835 caused Gitk and Git GUI to not work properly on Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and
were disabled in USN-7626-2. The problematic updates for the
aforementioned CVEs have now been corrected and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If
Ubuntu
Git regression
vendor_ubuntu·2025-07-09·CVSS 3.6
CVE-2025-27613 [LOW] Git regression
Title: Git regression
Summary: USN-7626-1 introduced a regression in Git.
USN-7626-1 fixed vulnerabilities in Git. The update introduced a regression
in gitk and git-gui. This update reverts the corresponding fixes for
CVE-2025-27613 and CVE-2025-46835 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue on
Ubuntu
Git vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 3.6
CVE-2025-46835 [LOW] Git vulnerabilities
Title: Git vulnerabilities
Summary: Several security issues were fixed in Git.
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and
Ubuntu 25.04. (CVE-2025-27614)
Johannes Sixt discovered that Git incorrectly managed file modification
constraints with Git GUI. If a user were tricked into editing a file in a
malicious Git repository, an attacker could p
Microsoft
GitHub: CVE-2025-46835 Git File Overwrite Vulnerability
vendor_msrc·2025-07-08·CVSS 8.5
CVE-2025-46835 [HIGH] GitHub: CVE-2025-46835 Git File Overwrite Vulnerability
GitHub: CVE-2025-46835 Git File Overwrite Vulnerability
Description: CVE-2025-46835 is regarding a vulnerability in Git GUI where when a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite any writable file. GitHub created this CVE on their behalf. The documented Visual Studio updates incorporate updates in GitK which address this vulnerability.
Please see CVE-2025-46835 for more information.
Visual Studio: Visual Studio
GitHub: GitHub
Customer Action Required: Yes
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8
Reference: https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
Reference
Debian
CVE-2025-46835: git - Git GUI allows you to use the Git source control management tools via a GUI. Whe...
vendor_debian·2025·CVSS 8.5
CVE-2025-46835 [HIGH] CVE-2025-46835: git - Git GUI allows you to use the Git source control management tools via a GUI. Whe...
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
Scope: local
bookworm: resolved (fixed in 1:2.39.5-0+deb12u3)
bullseye: resolved (fixed in 1:2.30.2-1+deb11u5)
forky: resolved (fixed in 1:2.50.1-0.1)
sid: resolved (fixed in 1:2.50.1-0.1)
trixie: resolved (fixed in 1:2.47.3-0+deb13u1)
Microsoft
drm/amdgpu: Fix smatch static checker warning
vendor_msrc·2024-09-10·CVSS 5.5
CVE-2024-46835 [MEDIUM] CWE-476 drm/amdgpu: Fix smatch static checker warning
drm/amdgpu: Fix smatch static checker warning
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft
OSV
CVE-2025-46835: Git GUI allows you to use the Git source control management tools via a GUI
osv·2025-07-10·CVSS 8.5
CVE-2025-46835 [HIGH] CVE-2025-46835: Git GUI allows you to use the Git source control management tools via a GUI
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
OSV
git regression
osv·2025-07-10·CVSS 3.6
CVE-2025-27613 [LOW] git regression
git regression
USN-7626-1 fixed vulnerabilities in Git. The updates for CVE-2025-27613
and CVE-2025-46835 caused Gitk and Git GUI to not work properly on Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and
were disabled in USN-7626-2. The problematic updates for the
aforementioned CVEs have now been corrected and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repositor
OSV
git regression
osv·2025-07-09·CVSS 3.6
CVE-2025-27613 [LOW] git regression
git regression
USN-7626-1 fixed vulnerabilities in Git. The update introduced a regression
in gitk and git-gui. This update reverts the corresponding fixes for
CVE-2025-27613 and CVE-2025-46835 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and
Ubuntu 25.04
OSV
git vulnerabilities
osv·2025-07-08·CVSS 3.6
CVE-2025-27613 [LOW] git vulnerabilities
git vulnerabilities
Avi Halachmi discovered that Git incorrectly managed file modification
constraints with Gitk. An attacker could possibly use this issue to create
or write to arbitrary files on the system. (CVE-2025-27613)
Avi Halachmi discovered that Git incorrectly handled arguments when
invoking the Gitk utility. If a user were tricked into cloning a malicious
Git repository, an attacker could possibly use this issue to run arbitrary
commands. This issue only affected Ubuntu 24.04 LTS, Ubuntu 24.10, and
Ubuntu 25.04. (CVE-2025-27614)
Johannes Sixt discovered that Git incorrectly managed file modification
constraints with Git GUI. If a user were tricked into editing a file in a
malicious Git repository, an attacker could possibly use this issue to
create or write to arbitrary files
No detection rules found.
No public exploits indexed.
https://github.com/j6t/git-gui/compare/dcda716dbc9c90bcac4611bd1076747671ee0906..a437f5bc93330a70b42a230e52f3bd036ca1b1dahttps://github.com/j6t/git-gui/security/advisories/GHSA-xfx7-68v4-v8fghttp://www.openwall.com/lists/oss-security/2025/07/08/4https://lists.debian.org/debian-lts-announce/2025/10/msg00003.html
2025-07-10
Published