From 913cd1e0132407e158cad7e4bc0f4e4fa937f183 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 16 Jul 2026 09:07:58 -1000 Subject: Reject option-like revisions in the log walk The log page passed the `id` query parameter to git's revision parser without resolving it and ahead of the end-of-options marker. A value like `id=--output=/path` was then parsed as an option, so an unauthenticated request could create or truncate any file the server user could write. No valid ref or object name begins with a dash. --- source/ui-log.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/source/ui-log.c b/source/ui-log.c index d3610d3..0a3fc0a 100644 --- a/source/ui-log.c +++ b/source/ui-log.c @@ -381,6 +381,18 @@ void cgit_print_log(const char *tip, int ofs, int cnt, char *grep, char *pattern if (!tip) tip = ctx.qry.head; tip = disambiguate_ref(tip, &must_free_tip); + if (tip && tip[0] == '-') { + /* setup_revisions() parses a leading-dash argument as an + * option, so a tip like the id= value "--output=" would + * be handled by git as a request to write an arbitrary file. + * No valid ref or object name begins with a dash, so refuse it. + */ + cgit_print_error_page(400, "Bad request", "Invalid revision"); + if (must_free_tip) + free((char *)tip); + strvec_clear(&rev_argv); + return; + } strvec_push(&rev_argv, tip); if (grep && pattern && *pattern) { -- cgit v2.8.0