Replace the index with a valid empty one so downstream tools never read attacker-controlled index entries (CVE-2025-10283).
(folder)
| 283 | |
| 284 | @staticmethod |
| 285 | def _write_empty_index(folder): |
| 286 | """Replace the index with a valid empty one so downstream tools |
| 287 | never read attacker-controlled index entries (CVE-2025-10283).""" |
| 288 | import hashlib |
| 289 | import struct |
| 290 | |
| 291 | header = b"DIRC" + struct.pack(">II", 2, 0) |
| 292 | index_path = folder / ".git" / "index" |
| 293 | if index_path.exists(): |
| 294 | index_path.write_bytes(header + hashlib.sha1(header).digest()) |