Logo
vulnerabilityCVE-2025-27614
Name
CVE-2025-27614
Source
NVD ( link)Debian ( link)
Description
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
git
Patched

Vulnerability Ratings#


8.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.48.2
Not Affected
buildroot
master
2.54.0
Not Affected
openwrt
master
2.50.1-r1
Not Affected
openwrt
openwrt-25.12
2.50.1-r1
Not Affected
yocto
master
2.54.0
Not Affected
yocto
scarthgap
2.44.4
Not Affected

Resolved with patches#


git (yocto:kirkstone)

#
Title
Author
Resolve
1
Patch #1
d61cfed2c23705fbeb9c0d08f59e75ee08738950 Merge: 664d4fa692 311d9ada3a
CVE-2025-27613
CVE-2025-27614
CVE-2025-46334
CVE-2025-46835