PT-2026-78400 · Pypi+1 · Gitpython+1

·

CVE-2026-76218

·

Published

2026-08-07

·

Updated

2026-09-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.58
Description A remote code execution issue exists in the Repo.init() function. The software forwards unsafe git options without proper validation, allowing an attacker to provide a template parameter that points to a directory containing malicious git hooks. These hooks can then execute arbitrary code when git operations are performed on the initialized repository.
Recommendations Update GitPython to version 3.1.58 or later.

Exploit

Fix

RCE

Code Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76218
GHSA-298H-JPQ4-M665
GHSA-9RJ7-RF2P-W77R
PYSEC-2026-3840

Affected Products

Gitpython
Red Os