{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-76222/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-76221"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GitPython"],"_cs_severities":["high"],"_cs_tags":["supply-chain","path-traversal","gitpython","cve-2026-76222"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eGitPython, a widely used Python library for interacting with Git repositories, contains a configuration-name injection vulnerability in its option-name validator (CVE-2026-76221). The vulnerability exists in all versions prior to 3.1.58. It stems from improper neutralization of special characters - specifically equals signs, hash symbols, and whitespace - within the option-name validation logic.\u003c/p\u003e\n\u003cp\u003eAn attacker capable of influencing the arguments passed to GitPython's configuration management functions can inject arbitrary git-config directives. By crafting malicious option names such as 'sshCommand = [command] #', an attacker can manipulate sensitive Git configuration keys like 'core.sshCommand' or 'core.hooksPath'. When the affected system performs a subsequent Git operation, the injected configuration is honored, leading to remote code execution (RCE) in the context of the user running the GitPython-powered application. This vulnerability is significant for CI/CD pipelines, web-based repository viewers, and automated build tools that leverage GitPython to process untrusted repository metadata.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary command execution on systems running applications that use affected versions of GitPython. Given GitPython's prevalence in developer tooling, CI/CD runners, and automated security scanning platforms, the impact includes unauthorized code execution, potential pipeline compromise, and lateral movement within the development environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade GitPython to version 3.1.58 or later immediately across all environments.\u003c/li\u003e\n\u003cli\u003eAudit applications using GitPython to ensure they do not pass unsanitized user-controlled input into Git configuration methods or option-name validators.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious git-related configuration changes, such as unexpected setting of 'core.sshCommand' or 'core.hooksPath' via process command-line auditing.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T14:35:09Z","date_published":"2026-08-19T14:35:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gitpython-config-injection/","summary":"GitPython versions prior to 3.1.58 are vulnerable to configuration-name injection, allowing attackers to forge arbitrary git-config directives and execute commands via core.sshCommand or core.hooksPath.","title":"GitPython Configuration-Name Injection Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-gitpython-config-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-76222","version":"https://jsonfeed.org/version/1.1"}