GitPython Repository Discovery Vulnerability Leading to RCE
GitPython versions up to 3.1.59 are vulnerable to an arbitrary code execution flaw where malicious tracked repository content is misidentified as a Git directory, causing hooks to execute during standard repository operations.
CVE search metadata
CVE search record: CVE-2026-87817. Severity: high. CVSS: 8.8. EPSS: 0.40%. KEV: no. Product: GitPython (<= 3.1.59). Brief: GitPython Repository Discovery Vulnerability Leading to RCE. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gitpython-rce/
GitPython versions through 3.1.59 contain a flaw in the Repo.__init__ discovery logic that incorrectly resolves the git directory. The library tests candidate paths in an order that prioritizes arbitrary files over the actual .git directory. An attacker can place specially crafted files, including hooks/, HEAD, config, and commondir, at the root of a tracked repository. When a victim uses GitPython to clone or interact with this repository, the library misidentifies the working-tree root as the git directory. This allows the attacker to gain code execution by placing an executable pre-commit hook in the repository, which is triggered when index.commit() is called. Additionally, the library's misidentification allows for arbitrary file reading via malicious config includes, as the parser follows relative paths to sensitive files such as ~/.aws/credentials. This vulnerability affects automated systems like CI runners, code-scanning services, and AI agents that process untrusted repositories.
Attack Chain
- Attacker creates a repository containing tracked files named
gitdir,commondir, andHEADat the root. - Attacker places a malicious executable script in
hooks/pre-commit(mode 100755). - Victim application clones or opens the attacker-controlled repository using
git.Repo(). - GitPython discovery logic iterates through the root files and incorrectly resolves the working-tree root as the git directory.
- GitPython sets the internal
git_dirto the attacker's chosen path. - Victim application calls
index.commit(), prompting GitPython to search for and execute hooks from the misidentified path. - The
pre-commithook executes with the permissions of the victim process.
Impact
Successful exploitation allows for arbitrary code execution in the context of the user or service running the GitPython library. This impacts automated CI/CD pipelines, code analysis services, and developer workstations. The vulnerability also enables unauthorized file disclosure by forcing the parser to merge malicious git configuration files, potentially exfiltrating sensitive credentials or system files.
Recommendation
- Upgrade GitPython to a patched version once available (as of publication, versions <= 3.1.59 are confirmed vulnerable).
- Avoid processing untrusted or unverified repositories using GitPython
index.commit()or similar methods that trigger hook execution. - For CI/CD and automated pipelines, implement strict sandboxing or containerization when running GitPython to minimize the impact of potential command execution.
- Audit internal codebases for usage of
git.Repo.clone_fromorgit.Repo()where the source repository is provided by external or untrusted users.
Immediate actions
Audit codebase for GitPython usage in automated pipelines
Mitigations
Upgrade GitPython to 3.1.60 or later
CVE-2026-87817