« Volver al listado

CVE-2025-46835

Estado: AplazadaAlta (8.5)—

Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L + UI:R (usuario edita archivo en directorio con nombre malicioso) = explotación en cliente. Impacto principal: sobrescritura de archivos (CWE-88, manipulación de datos T1565.001). Riesgo secundario: ejecución si se sobrescriben scripts o configuración (T1059).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-46835",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-46835",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-10T15:53:11.968495Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.5,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "j6t",
          "product": "git-gui",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.43.7"
            },
            {
              "status": "affected",
              "version": ">= 2.44.0, < 2.44.4"
            },
            {
              "status": "affected",
              "version": ">= 2.45.0, < 2.45.4"
            },
            {
              "status": "affected",
              "version": ">= 2.46.0, < 2.46.4"
            },
            {
              "status": "affected",
              "version": ">= 2.47.0, < 2.47.3"
            },
            {
              "status": "affected",
              "version": ">= 2.48.0, < 2.48.2"
            },
            {
              "status": "affected",
              "version": ">= 2.49.0, < 2.49.1"
            },
            {
              "status": "affected",
              "version": ">= 2.50.0, < 2.50.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-10T15:15:29.503",
  "references": [
    {
      "url": "https://github.com/j6t/git-gui/compare/dcda716dbc9c90bcac4611bd1076747671ee0906..a437f5bc93330a70b42a230e52f3bd036ca1b1da",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/j6t/git-gui/security/advisories/GHSA-xfx7-68v4-v8fg",
      "source": "security-advisories@github.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/07/08/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00003.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-88"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user has write permission. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1."
    },
    {
      "lang": "es",
      "value": "Git GUI permite usar las herramientas de gestión de control de código fuente de Git mediante una interfaz gráfica de usuario. Cuando un usuario clona un repositorio no confiable y se le induce a editar un archivo ubicado en un directorio malicioso del repositorio, la interfaz gráfica de Git puede crear y sobrescribir archivos para los que el usuario tiene permiso de escritura. Esta vulnerabilidad está corregida en las versiones 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1 y 2.50.1."
    }
  ],
  "lastModified": "2026-06-17T09:27:00.533",
  "sourceIdentifier": "security-advisories@github.com"
}