CVE-2026-52726: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in jelmer dulwich
Dulwich, a pure-Python Git implementation, has a path traversal vulnerability in versions starting from 0.23.2 up to but not including 1.2.5. The vulnerability occurs in the submodule update functionality, where attacker-controlled submodule paths from a crafted repository are not properly validated. This allows an attacker to write malicious executables into the victim's .git/hooks directory, which are then executed by subsequent Git or Dulwich commands invoking those hooks, leading to arbitrary code execution. Version 1.2.5 addresses this issue.
AI Analysis
Technical Summary
CVE-2026-52726 is a path traversal vulnerability (CWE-22) in the Dulwich library's submodule update mechanism. Specifically, dulwich.porcelain.submodule_update and porcelain.clone with recurse_submodules=True do not validate submodule paths from a malicious .gitmodules file and corresponding gitlink tree entries. This flaw enables an attacker to place executable files into sensitive directories inside the parent repository's .git directory, such as .git/hooks, preserving executable permissions. When Git or Dulwich subsequently runs hooks from these directories, the attacker's code executes. This vulnerability parallels fixes made in upstream Git for CVE-2024-32002 and CVE-2024-32004 but was not applied to Dulwich until version 1.2.5, which patches the issue.
Potential Impact
An attacker who controls or can influence the upstream repository can craft submodules that cause malicious executables to be written into the victim's .git/hooks directory. These executables run with the privileges of the user executing Git or Dulwich commands that trigger the hooks, resulting in arbitrary code execution. This can lead to full compromise of the user's environment where Dulwich is used.
Mitigation Recommendations
Version 1.2.5 of Dulwich patches this vulnerability. Users should upgrade to version 1.2.5 or later to remediate the issue. No official fix or temporary workaround is documented in the provided data. Patch status is not yet confirmed beyond the indication that 1.2.5 includes the fix; users should verify with the vendor advisory for the latest remediation guidance.
CVE-2026-52726: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in jelmer dulwich
Description
Dulwich, a pure-Python Git implementation, has a path traversal vulnerability in versions starting from 0.23.2 up to but not including 1.2.5. The vulnerability occurs in the submodule update functionality, where attacker-controlled submodule paths from a crafted repository are not properly validated. This allows an attacker to write malicious executables into the victim's .git/hooks directory, which are then executed by subsequent Git or Dulwich commands invoking those hooks, leading to arbitrary code execution. Version 1.2.5 addresses this issue.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-52726 is a path traversal vulnerability (CWE-22) in the Dulwich library's submodule update mechanism. Specifically, dulwich.porcelain.submodule_update and porcelain.clone with recurse_submodules=True do not validate submodule paths from a malicious .gitmodules file and corresponding gitlink tree entries. This flaw enables an attacker to place executable files into sensitive directories inside the parent repository's .git directory, such as .git/hooks, preserving executable permissions. When Git or Dulwich subsequently runs hooks from these directories, the attacker's code executes. This vulnerability parallels fixes made in upstream Git for CVE-2024-32002 and CVE-2024-32004 but was not applied to Dulwich until version 1.2.5, which patches the issue.
Potential Impact
An attacker who controls or can influence the upstream repository can craft submodules that cause malicious executables to be written into the victim's .git/hooks directory. These executables run with the privileges of the user executing Git or Dulwich commands that trigger the hooks, resulting in arbitrary code execution. This can lead to full compromise of the user's environment where Dulwich is used.
Mitigation Recommendations
Version 1.2.5 of Dulwich patches this vulnerability. Users should upgrade to version 1.2.5 or later to remediate the issue. No official fix or temporary workaround is documented in the provided data. Patch status is not yet confirmed beyond the indication that 1.2.5 includes the fix; users should verify with the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-08T14:00:43.571Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a29e5e631875706499a3a1b
Added to database: 06/10/2026, 22:32:06 UTC
Last enriched: 07/02/2026, 23:17:04 UTC
Last updated: 07/25/2026, 20:52:05 UTC
Views: 129
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.