PT-2026-71450 · Pypi+1 · Gitpython+1
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.55
Description
Improper handling of URL expansion in
Remote.create() and Submodule.add() allows for the exfiltration of secrets. Attackers can provide URLs containing environment variable tokens that are expanded into the .git/config and .gitmodules files. These secrets are then transmitted to attacker-controlled hosts during fetch or pull operations.Recommendations
Update GitPython to version 3.1.55 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os