CVE-2025-46835 is a high-severity vulnerability affecting Git GUI, allowing for arbitrary file creation and overwrite. An attacker can exploit this by tricking a user into cloning an untrusted repository and editing a file within a maliciously named directory, leading to high impact on confidentiality and integrity, and low impact on availability. This vulnerability has a CVSS score of 8.5 (HIGH) and is fixed in Git GUI versions 2.43.7 and later. While there is no known active exploitation or public exploit code, it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| J6t | Git-Gui | < 2.43.7, >= 2.44.0, < 2.44.4, >= 2.45.0, < 2.45.4, >= 2.46.0, < 2.46.4, >= 2.47.0, < 2.47.3, >= 2.48.0, < 2.48.2, >= 2.49.0, < 2.49.1, >= 2.50.0, < 2.50.1CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.