CVE-2023-23946 is a path-traversal vulnerability in Git's git apply command affecting versions before 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. A crafted patch can create a symbolic link and subsequently create or overwrite a file through that link outside the repository working tree. The write occurs with the filesystem permissions of the user executing git apply.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
git apply to overwrite filesystem paths outside the working tree that are writable by the user applying the crafted patch. This can compromise the integrity of user-accessible files.If you can’t patch tonight, do this now.
git apply --stat. Do not apply a patch that creates a symbolic link and then creates a file beyond that symbolic link.Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Bash-based proof of concept for CVE-2023-23946 in Git. It contains two files: a README describing the vulnerability and usage, and a single executable script, exploit.sh, which is the main exploit logic. The script is interactive: it asks the operator for a target directory to symlink, a filename to create under that directory, and arbitrary file contents to embed in the patch. It then creates a temporary repository under /tmp/cve_git_patch, initializes Git, commits a symlink pointing to the chosen target directory, and generates a malicious patch file named exploit.patch. The patch performs a rename from symlink to renamed-symlink and adds a new file beneath the renamed symlink path, causing vulnerable Git patch handling to write attacker-controlled content into the symlink target when applied by the victim. The printed example command shows the intended abuse path: a different user runs /usr/bin/git apply against the crafted patch, potentially enabling local privilege abuse or lateral access, such as planting an SSH authorized_keys file. There are no network callbacks or remote C2 endpoints in the exploit itself; it is a local file-manipulation exploit that weaponizes Git patch application behavior.
This repository provides a proof-of-concept (POC) exploit for CVE-2023-23946, a vulnerability in git's handling of symbolic links. The exploit consists of a README.md explaining the vulnerability and exploitation steps, and an 'exploit.patch' file that demonstrates the attack. The attack involves creating a symbolic link in the repository that points outside the working tree, then applying a crafted patch that renames the symlink and writes arbitrary content to a file outside the repository. This leverages git's improper protections against symlink manipulation during patch application, allowing an attacker to write to arbitrary files on the filesystem. The exploit is local in nature and requires the attacker to have access to a vulnerable git repository. The main fingerprintable endpoint is the file path outside the working tree that the attacker targets for writing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network-accessible, low-complexity vulnerability with no required privileges or user interaction that can compromise integrity, rated Important by the referenced CentOS local security check.
A vulnerability tracked as CVE-2023-23946 affecting Unity Linux systems; the referenced local-security-check plugin indicates exploit availability and a published patch.
Unknown.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.