Skip to content
Threat Feed

Product

GitPython

4 briefs RSS
high advisory

GitPython Configuration-Name Injection Vulnerability

GitPython versions prior to 3.1.58 are vulnerable to configuration-name injection, allowing attackers to forge arbitrary git-config directives and execute commands via core.sshCommand or core.hooksPath.

GitPython supply-chain path-traversal cve-2026-76222
2t 1c
high advisory

Path Traversal in GitPython via Malicious Submodule Names

GitPython fails to validate submodule names defined in .gitmodules files, allowing attackers to perform path traversal and create arbitrary Git repositories outside the intended working tree during submodule initialization.

GitPython +1 remote-code-execution input-validation python
1t 1c
high advisory

Command Injection Vulnerability in GitPython

GitPython versions prior to 3.1.51 are vulnerable to command injection because the library's security blocklist fails to account for Git command-line option abbreviation, allowing attackers to execute arbitrary commands.

GitPython vulnerability command-injection python
1t 1c
high advisory

GitPython Vulnerability Allows Arbitrary Code Execution via Git Hooks

A vulnerability in GitPython versions prior to 3.1.47 allows for command execution during repository cloning by manipulating the `multi_options` parameter to inject malicious Git configurations, such as `core.hooksPath`, leading to the execution of attacker-controlled hooks.

GitPython code-execution git-hooks command-injection
2r 1t 1c