{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agitpython_projectgitpython/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:*","cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-87817"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GitPython (\u003c= 3.1.59)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","gitpython","software-vulnerability"],"_cs_type":"advisory","_cs_vendors":["GitPython"],"content_html":"\u003cp\u003eGitPython versions through 3.1.59 contain a flaw in the \u003ccode\u003eRepo.__init__\u003c/code\u003e discovery logic that incorrectly resolves the git directory. The library tests candidate paths in an order that prioritizes arbitrary files over the actual \u003ccode\u003e.git\u003c/code\u003e directory. An attacker can place specially crafted files, including \u003ccode\u003ehooks/\u003c/code\u003e, \u003ccode\u003eHEAD\u003c/code\u003e, \u003ccode\u003econfig\u003c/code\u003e, and \u003ccode\u003ecommondir\u003c/code\u003e, at the root of a tracked repository. When a victim uses GitPython to clone or interact with this repository, the library misidentifies the working-tree root as the git directory. This allows the attacker to gain code execution by placing an executable \u003ccode\u003epre-commit\u003c/code\u003e hook in the repository, which is triggered when \u003ccode\u003eindex.commit()\u003c/code\u003e is called. Additionally, the library's misidentification allows for arbitrary file reading via malicious \u003ccode\u003econfig\u003c/code\u003e includes, as the parser follows relative paths to sensitive files such as \u003ccode\u003e~/.aws/credentials\u003c/code\u003e. This vulnerability affects automated systems like CI runners, code-scanning services, and AI agents that process untrusted repositories.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates a repository containing tracked files named \u003ccode\u003egitdir\u003c/code\u003e, \u003ccode\u003ecommondir\u003c/code\u003e, and \u003ccode\u003eHEAD\u003c/code\u003e at the root.\u003c/li\u003e\n\u003cli\u003eAttacker places a malicious executable script in \u003ccode\u003ehooks/pre-commit\u003c/code\u003e (mode 100755).\u003c/li\u003e\n\u003cli\u003eVictim application clones or opens the attacker-controlled repository using \u003ccode\u003egit.Repo()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eGitPython discovery logic iterates through the root files and incorrectly resolves the working-tree root as the git directory.\u003c/li\u003e\n\u003cli\u003eGitPython sets the internal \u003ccode\u003egit_dir\u003c/code\u003e to the attacker's chosen path.\u003c/li\u003e\n\u003cli\u003eVictim application calls \u003ccode\u003eindex.commit()\u003c/code\u003e, prompting GitPython to search for and execute hooks from the misidentified path.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003epre-commit\u003c/code\u003e hook executes with the permissions of the victim process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in the context of the user or service running the GitPython library. This impacts automated CI/CD pipelines, code analysis services, and developer workstations. The vulnerability also enables unauthorized file disclosure by forcing the parser to merge malicious git configuration files, potentially exfiltrating sensitive credentials or system files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade GitPython to a patched version once available (as of publication, versions \u0026lt;= 3.1.59 are confirmed vulnerable).\u003c/li\u003e\n\u003cli\u003eAvoid processing untrusted or unverified repositories using GitPython \u003ccode\u003eindex.commit()\u003c/code\u003e or similar methods that trigger hook execution.\u003c/li\u003e\n\u003cli\u003eFor CI/CD and automated pipelines, implement strict sandboxing or containerization when running GitPython to minimize the impact of potential command execution.\u003c/li\u003e\n\u003cli\u003eAudit internal codebases for usage of \u003ccode\u003egit.Repo.clone_from\u003c/code\u003e or \u003ccode\u003egit.Repo()\u003c/code\u003e where the source repository is provided by external or untrusted users.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T04:21:35Z","date_published":"2026-10-01T04:21:35Z","id":"https://feed.craftedsignal.io/briefs/2026-10-gitpython-rce/","summary":"GitPython versions up to 3.1.59 are vulnerable to an arbitrary code execution flaw where malicious tracked repository content is misidentified as a Git directory, causing hooks to execute during standard repository operations.","title":"GitPython Repository Discovery Vulnerability Leading to RCE","url":"https://feed.craftedsignal.io/briefs/2026-10-gitpython-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}