PT-2026-78403 · Pypi+1 · Gitpython+1

·

CVE-2026-76221

·

Published

2026-08-04

·

Updated

2026-09-01

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.58
Description A config-name injection issue exists in the option-name validator. This allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. By using malicious option names such as sshCommand = touch /tmp/RCE #, an attacker can execute arbitrary commands through core.sshCommand or core.hooksPath during the subsequent git operation.
Recommendations Update GitPython to version 3.1.58 or later.

Exploit

Fix

DoS

RCE

Argument Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12061
CVE-2026-76221
GHSA-JM78-9FVV-MHGR
OPENSUSE-SU-2026:11566-1
PYSEC-2026-3783

Affected Products

Gitpython
Red Os