← voltar
CVE-2025-46835

Git GUI can create and overwrite files for which the user has write permission

CVSS 8.5 HIGHEPSS 0.3%CWE-88
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
10 jul 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
Produtos afetados
j6t · git-gui

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →