PT-2026-78404 · Pypi+1 · Gitpython+1
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.58
Description
GitPython fails to validate submodule names within
.gitmodules files. This allows an attacker to use traversal sequences in submodule names during submodule initialization to create Git repositories at arbitrary filesystem paths outside the intended clone directory.Recommendations
Update GitPython to version 3.1.58 or later.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os