« Volver al listado

CVE-2025-46334

Estado: AplazadaAlta (8.6)—

Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory. The mentioned programs are invoked when the user selects Git Bash or Browse Files from the menu. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R (interacción del usuario al seleccionar menú Git Bash) → T1203. El repositorio malicioso contiene sh.exe o filtros textconv comprometidos que se ejecutan cuando el usuario interactúa, resultando en ejecución de comandos (T1059) con C:H/I:H/A:H.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-46334",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-46334",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-10T15:54:14.118257Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "j6t",
          "product": "git-gui",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.43.7"
            },
            {
              "status": "affected",
              "version": ">= 2.44.0, < 2.44.4"
            },
            {
              "status": "affected",
              "version": ">= 2.45.0, < 2.45.4"
            },
            {
              "status": "affected",
              "version": ">= 2.46.0, < 2.46.4"
            },
            {
              "status": "affected",
              "version": ">= 2.47.0, < 2.47.3"
            },
            {
              "status": "affected",
              "version": ">= 2.48.0, < 2.48.2"
            },
            {
              "status": "affected",
              "version": ">= 2.49.0, < 2.49.1"
            },
            {
              "status": "affected",
              "version": ">= 2.50.0, < 2.50.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-10T15:15:28.417",
  "references": [
    {
      "url": "https://github.com/j6t/git-gui/compare/dcda716dbc9c90bcac4611bd1076747671ee0906..a1ccd2512072cf52835050f4c97a4fba9f0ec8f9",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/j6t/git-gui/security/advisories/GHSA-7px4-9hg2-fvhx",
      "source": "security-advisories@github.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/07/08/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of sh.exe or typical textconv filter programs such as astextplain. Due to the unfortunate design of Tcl on Windows, the search path when looking for an executable always includes the current directory. The mentioned programs are invoked when the user selects Git Bash or Browse Files from the menu. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1."
    },
    {
      "lang": "es",
      "value": "Git GUI permite usar las herramientas de gestión del control de código fuente de Git mediante una interfaz gráfica. Un repositorio malicioso puede incluir versiones de sh.exe o programas de filtrado textconv típicos, como astextplain. Debido al diseño deficiente de Tcl en Windows, la ruta de búsqueda de un ejecutable siempre incluye el directorio actual. Estos programas se invocan cuando el usuario selecciona Git Bash o \"Explorar archivos\" en el menú. Esta vulnerabilidad está corregida en las versiones 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1 y 2.50.1."
    }
  ],
  "lastModified": "2026-06-17T09:26:15.297",
  "sourceIdentifier": "security-advisories@github.com"
}