PT-2026-67419 · Pypi+1 · Gitpython+1
CVE-2026-69097
·
Published
2026-07-20
·
Updated
2026-09-04
CVSS v4.0
7.3
High
| Vector | AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.53
Description
Improper escaping of section names in git config files allows the injection of arbitrary configuration directives through malicious submodule names. By utilizing the
create submodule or clone from operations, an attacker can inject dangerous configuration keys, such as core.sshCommand, into the .git/config file. This can lead to remote code execution when git performs SSH operations.Recommendations
Update GitPython to version 3.1.53 or later.
Exploit
Fix
RCE
DoS
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitpython
Red Os