CVE-2025-27614 Details
Description
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that with some social engineering a user who has cloned the repository can be tricked into running any script (e.g., Bourne shell, Perl, Python, ...) supplied by the attacker by invoking gitk filename, where filename has a particular structure. The script is run with the privileges of the user. This vulnerability is fixed in 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.
A vulnerability in Gitk, a Tcl/Tk-based Git history browser, allows for arbitrary command execution. This issue affects Gitk versions 2.41.0 through 2.50.0. The vulnerability arises from improper handling of file arguments, which can be exploited through social engineering. An attacker can craft a Git repository that, when cloned by a user and opened with Gitk, executes a script (such as a Bourne shell, Perl, or Python script) with the user's privileges.
Users can upgrade to Gitk versions 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, or 2.50.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2025CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/07/08/4 | CVE | |
| https://github.com/j6t/gitk/commit/8e3070aa5e331be45d4d03e3be41f84494fce129 | [email protected] | Source CodeVendor |
| https://github.com/j6t/gitk/security/advisories/GHSA-g4v5-fjv9-mhhc | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| j6t gitk | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Jul 10, 2025 | New CVE Received | [email protected] |
Volerion