PT-2026-78403 · Pypi+1 · Gitpython+1
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.58
Description
A config-name injection issue exists in the option-name validator. This allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. By using malicious option names such as
sshCommand = touch /tmp/RCE #, an attacker can execute arbitrary commands through core.sshCommand or core.hooksPath during the subsequent git operation.Recommendations
Update GitPython to version 3.1.58 or later.
Exploit
Fix
DoS
RCE
Argument Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os