CVE-2025-27614

Source
https://cve.org/CVERecord?id=CVE-2025-27614
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-27614.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-27614
Aliases
  • GHSA-g4v5-fjv9-mhhc
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (4)
DEBIAN (1)
ECHO (1)
OESA (3)
openSUSE (1)
RHSA (3)
RLSA (2)
ROOT (1)
SUSE (4)
UBUNTU (1)
Related
Published
2025-07-10T15:02:25Z
Modified
2026-09-21T03:30:29Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Gitk allows arbitrary command execution
Details

Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-78"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27614.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "2.41.0"
                },
                {
                    "fixed":  "2.43.7"
                },
                {
                    "introduced":  "2.44.0"
                },
                {
                    "fixed":  "2.44.4"
                },
                {
                    "introduced":  "2.45.0"
                },
                {
                    "fixed":  "2.45.4"
                },
                {
                    "introduced":  "2.46.0"
                },
                {
                    "fixed":  "2.46.4"
                },
                {
                    "introduced":  "2.47.0"
                },
                {
                    "fixed":  "2.47.3"
                },
                {
                    "introduced":  "2.48.0"
                },
                {
                    "fixed":  "2.48.2"
                },
                {
                    "introduced":  "2.49.0"
                },
                {
                    "fixed":  "2.49.1"
                },
                {
                    "introduced":  "2.50.0"
                },
                {
                    "fixed":  "2.50.1"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/j6t/gitk

Affected ranges

Type
GIT
Repo
https://github.com/j6t/gitk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-27614.json"