PT-2026-71450 · Pypi+1 · Gitpython+1

·

CVE-2026-73622

·

Published

2026-07-24

·

Updated

2026-09-08

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.55
Description Improper handling of URL expansion in Remote.create() and Submodule.add() allows for the exfiltration of secrets. Attackers can provide URLs containing environment variable tokens that are expanded into the .git/config and .gitmodules files. These secrets are then transmitted to attacker-controlled hosts during fetch or pull operations.
Recommendations Update GitPython to version 3.1.55 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73622
GHSA-94P4-4CQ8-9G67
PYSEC-2026-3951

Affected Products

Gitpython
Red Os