<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agitpython_projectgitpython/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 04:21:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agitpython_projectgitpython/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>GitPython Repository Discovery Vulnerability Leading to RCE</title><link>https://feed.craftedsignal.io/briefs/2026-10-gitpython-rce/</link><pubDate>Thu, 01 Oct 2026 04:21:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gitpython-rce/</guid><description>GitPython versions up to 3.1.59 are vulnerable to an arbitrary code execution flaw where malicious tracked repository content is misidentified as a Git directory, causing hooks to execute during standard repository operations.</description><content:encoded><![CDATA[<p>GitPython versions through 3.1.59 contain a flaw in the <code>Repo.__init__</code> discovery logic that incorrectly resolves the git directory. The library tests candidate paths in an order that prioritizes arbitrary files over the actual <code>.git</code> directory. An attacker can place specially crafted files, including <code>hooks/</code>, <code>HEAD</code>, <code>config</code>, and <code>commondir</code>, at the root of a tracked repository. When a victim uses GitPython to clone or interact with this repository, the library misidentifies the working-tree root as the git directory. This allows the attacker to gain code execution by placing an executable <code>pre-commit</code> hook in the repository, which is triggered when <code>index.commit()</code> is called. Additionally, the library's misidentification allows for arbitrary file reading via malicious <code>config</code> includes, as the parser follows relative paths to sensitive files such as <code>~/.aws/credentials</code>. This vulnerability affects automated systems like CI runners, code-scanning services, and AI agents that process untrusted repositories.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker creates a repository containing tracked files named <code>gitdir</code>, <code>commondir</code>, and <code>HEAD</code> at the root.</li>
<li>Attacker places a malicious executable script in <code>hooks/pre-commit</code> (mode 100755).</li>
<li>Victim application clones or opens the attacker-controlled repository using <code>git.Repo()</code>.</li>
<li>GitPython discovery logic iterates through the root files and incorrectly resolves the working-tree root as the git directory.</li>
<li>GitPython sets the internal <code>git_dir</code> to the attacker's chosen path.</li>
<li>Victim application calls <code>index.commit()</code>, prompting GitPython to search for and execute hooks from the misidentified path.</li>
<li>The <code>pre-commit</code> hook executes with the permissions of the victim process.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution in the context of the user or service running the GitPython library. This impacts automated CI/CD pipelines, code analysis services, and developer workstations. The vulnerability also enables unauthorized file disclosure by forcing the parser to merge malicious git configuration files, potentially exfiltrating sensitive credentials or system files.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade GitPython to a patched version once available (as of publication, versions &lt;= 3.1.59 are confirmed vulnerable).</li>
<li>Avoid processing untrusted or unverified repositories using GitPython <code>index.commit()</code> or similar methods that trigger hook execution.</li>
<li>For CI/CD and automated pipelines, implement strict sandboxing or containerization when running GitPython to minimize the impact of potential command execution.</li>
<li>Audit internal codebases for usage of <code>git.Repo.clone_from</code> or <code>git.Repo()</code> where the source repository is provided by external or untrusted users.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>gitpython</category><category>software-vulnerability</category></item></channel></rss>