Remote Code Execution in GitPython via Git Config Injection
GitPython versions before 3.1.59 contain a vulnerability where improper sanitization of multi-line configuration values allows attackers to inject arbitrary git directives, leading to remote code execution.
CVE search metadata
CVE search record: CVE-2026-78676. Severity: critical. CVSS: 9.8. EPSS: 0.43%. KEV: no. Product: GitPython (< 3.1.59), GitPython (<= 3.1.58), GitPython (< 3.1.58). Brief: Remote Code Execution in GitPython via Git Config Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-08-gitpython-rce/
What's new
GitPython is a Python library used to interact with Git repositories. A critical vulnerability (CVE-2026-78676) exists in versions prior to 3.1.59 due to improper re-serialization of multi-line configuration values during git-config write operations. An attacker can supply a specially crafted configuration value containing embedded newlines. When GitPython performs a write operation on the configuration file, these newlines cause the injected content to be interpreted as new, live git configuration directives. A primary vector involves the injection of a malicious core.hooksPath, which directs Git to execute arbitrary code from a location controlled by the attacker whenever a Git hook is triggered. This vulnerability enables unauthenticated remote code execution in environments where GitPython processes untrusted configuration data.
Attack Chain
- The attacker provides a malicious, multi-line string intended to be written to a
.git/configfile (e.g., through an application interface using GitPython). - The application uses the vulnerable GitPython library to update the repository configuration with the attacker-controlled input.
- GitPython fails to escape or neutralize the newline characters within the input string during the serialization process.
- The serialized output is written to the
.git/configfile, effectively terminating the intended configuration key and starting a new directive on the subsequent line. - The injected directive, such as
core.hooksPath = /tmp/malicious_hooks_dir, is successfully written into the configuration file. - The system or user triggers a standard Git operation (e.g.,
git commitorgit push) within the repository. - Git reads the corrupted configuration file and executes the malicious scripts located in the attacker-specified hooks directory.
- Final objective achieved: Remote code execution under the context of the user running the Git operation.
Impact
The vulnerability carries a CVSS score of 9.8, indicating a critical risk of complete system compromise. Successful exploitation allows for unauthenticated remote code execution, which can lead to data exfiltration, unauthorized access to internal development environments, and the deployment of persistent backdoors within software supply chains. Any system or automated pipeline utilizing GitPython to manage repository configurations with untrusted input is at risk.
Recommendation
- Upgrade the
GitPythonlibrary to version 3.1.59 or later immediately to address CVE-2026-78676. - Audit application code that passes user-supplied input to GitPython's configuration write functions.
- Implement strict input validation to ensure configuration values do not contain newline characters or unexpected git directives.
- Review logs for unauthorized modifications to
.git/configfiles within critical infrastructure or CI/CD environments.
Immediate actions
Upgrade GitPython dependency to 3.1.59
Mitigations
Dependency update
CVE-2026-78676