PT-2026-71451 · Pypi+1 · Gitpython+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.54
Description
An incomplete denylist in
unsafe git clone options omits the --template option, which allows for arbitrary command execution during clone operations. An attacker can provide a --template value pointing to a directory containing malicious post-checkout hooks, which are scripts that run automatically after a repository is checked out, leading to code execution when the repository is cloned.Recommendations
Update GitPython to version 3.1.54 or later.
Exploit
Fix
OS Command Injection
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os