PT-2026-78404 · Pypi+1 · Gitpython+1

·

CVE-2026-76222

·

Published

2026-08-04

·

Updated

2026-09-01

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:P
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.58
Description GitPython fails to validate submodule names within .gitmodules files. This allows an attacker to use traversal sequences in submodule names during submodule initialization to create Git repositories at arbitrary filesystem paths outside the intended clone directory.
Recommendations Update GitPython to version 3.1.58 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12062
CVE-2026-76222
GHSA-3VRX-526R-64RM
GHSA-HMQ2-W58F-27JC
OPENSUSE-SU-2026:11566-1
PYSEC-2026-3784

Affected Products

Gitpython
Red Os