Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-46835

25
FAUCET Score

CVE-2025-46835 is a high-severity vulnerability affecting Git GUI, allowing for arbitrary file creation and overwrite. An attacker can exploit this by tricking a user into cloning an untrusted repository and editing a file within a maliciously named directory, leading to high impact on confidentiality and integrity, and low impact on availability. This vulnerability has a CVSS score of 8.5 (HIGH) and is fixed in Git GUI versions 2.43.7 and later. While there is no known active exploitation or public exploit code, it has garnered some community discussion and media coverage, indicating awareness.

Impacted Technologies

VendorProductVersion(s)CPE
J6tGit-Gui
< 2.43.7, >= 2.44.0, < 2.44.4, >= 2.45.0, < 2.45.4, >= 2.46.0, < 2.46.4, >= 2.47.0, < 2.47.3, >= 2.48.0, < 2.48.2, >= 2.49.0, < 2.49.1, >= 2.50.0, < 2.50.1CNA affected

CVSS Data

CVSS version used by this source: 3.1

8.5HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
21.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 20th percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Fixed in: 15.9.75
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.8Fixed in: 17.8.23
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.10Fixed in: 17.10.17
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.12Fixed in: 17.12.10
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2022 version 17.14Fixed in: 17.14.8
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Fixed in: 16.11.49
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: git-0:2.43.7-1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: git-0:2.47.3-1.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: git-0:2.47.3-1.el10_0
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/code-rhel9

Vendor Advisories (2)

redhatCVE-2025-46835Low

git: Git GUI can create and overwrite files for which the user has write permission

Jul 10, 2025
microsoft2025-Jul/CVE-2025-46835

GitHub: CVE-2025-46835 Git File Overwrite Vulnerability

Jul 8, 2025

References

lists.debian.org / debian-lts-announce/2025/10/msg00003.html
openwall.com / lists/oss-security/2025/07/08/4
github.com / j6t/git-gui/compare/dcda716dbc9c90bcac4611bd1076747671ee0906..a437f5bc93330a70b42a230e52f3bd036ca1b1da
github.com / j6t/git-gui/security/advisories/GHSA-xfx7-68v4-v8fg