cbcvebase.
CVE-2025-46835
published 2025-07-10

CVE-2025-46835: Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file…

PriorityP343high8.5CVSS 3.1
AVLACLPRNUIRSCCHIHAL
EPSS
0.30%
21.8th percentile
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiangit< git 1:2.39.5-0+deb12u3 (bookworm)git 1:2.39.5-0+deb12u3 (bookworm)
gitgit>= 0 < 1:2.30.2-1+deb11u51:2.30.2-1+deb11u5
gitgit>= 0 < 1:2.39.5-0+deb12u31:2.39.5-0+deb12u3
gitgit>= 0 < 1:2.47.3-0+deb13u11:2.47.3-0+deb13u1
gitgit>= 0 < 1:2.50.1-0.11:2.50.1-0.1
gitgit>= 0 < 1:2.34.1-1ubuntu1.141:2.34.1-1ubuntu1.14
gitgit>= 0 < 1:2.34.1-1ubuntu1.151:2.34.1-1ubuntu1.15
gitgit>= 0 < 1:2.34.1-1ubuntu1.131:2.34.1-1ubuntu1.13
gitgit>= 0 < 1:2.43.0-1ubuntu7.31:2.43.0-1ubuntu7.3
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm101:2.7.4-0ubuntu1.10+esm10
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm111:2.7.4-0ubuntu1.10+esm11
gitgit>= 0 < 1:2.7.4-0ubuntu1.10+esm91:2.7.4-0ubuntu1.10+esm9
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm31:2.17.1-1ubuntu0.18+esm3
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm41:2.17.1-1ubuntu0.18+esm4
gitgit>= 0 < 1:2.17.1-1ubuntu0.18+esm21:2.17.1-1ubuntu0.18+esm2
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm21:2.25.1-1ubuntu3.14+esm2
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm31:2.25.1-1ubuntu3.14+esm3
gitgit>= 0 < 1:2.25.1-1ubuntu3.14+esm11:2.25.1-1ubuntu3.14+esm1
j6tgit-gui< 2.43.72.43.7
j6tgit-gui
j6tgit-gui
j6tgit-gui
j6tgit-gui
j6tgit-gui
j6tgit-gui

CVSS provenance

nvdv3.18.5HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
osv8.5HIGH
vendor_debian8.5HIGH
vendor_msrc8.5HIGH
vendor_redhat8.5HIGH
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.