PT-2026-67419 · Pypi+1 · Gitpython+1

CVE-2026-69097

·

Published

2026-07-20

·

Updated

2026-09-04

CVSS v4.0

7.3

High

VectorAV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.53
Description Improper escaping of section names in git config files allows the injection of arbitrary configuration directives through malicious submodule names. By utilizing the create submodule or clone from operations, an attacker can inject dangerous configuration keys, such as core.sshCommand, into the .git/config file. This can lead to remote code execution when git performs SSH operations.
Recommendations Update GitPython to version 3.1.53 or later.

Exploit

Fix

RCE

DoS

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11004
CVE-2026-69097
GHSA-3RP5-JJMW-4WV2
OESA-2026-3353
OESA-2026-3354
OESA-2026-3439
OPENSUSE-SU-2026:11466-1

Affected Products

Gitpython
Red Os