CVE-2025-46835
Git GUI can create and overwrite files for which the user has write permission
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 jul 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Productos afectados
j6t · git-gui¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/j6t/git-gui/compare/dcda716dbc9c90bcac4611bd1076747671ee0906..a437f5bc93330a70b42a230e52f3bd036ca1b1dahttps://github.com/j6t/git-gui/security/advisories/GHSA-xfx7-68v4-v8fghttps://lists.debian.org/debian-lts-announce/2025/10/msg00003.htmlhttp://www.openwall.com/lists/oss-security/2025/07/08/4