PT-2026-78400 · Pypi+1 · Gitpython+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.58
Description
A remote code execution issue exists in the
Repo.init() function. The software forwards unsafe git options without proper validation, allowing an attacker to provide a template parameter that points to a directory containing malicious git hooks. These hooks can then execute arbitrary code when git operations are performed on the initialized repository.Recommendations
Update GitPython to version 3.1.58 or later.
Exploit
Fix
RCE
Code Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os