Impact
When gitk is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code.
Patches
Workarounds
Avoid using gitk (or Git GUI's "Visualize History" functionality) in clones of untrusted repositories.
References
Impact
When
gitkis run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code.Patches
Workarounds
Avoid using
gitk(or Git GUI's "Visualize History" functionality) in clones of untrusted repositories.References