PT-2026-81151 · Pypi+1 · Gitpython+1

·

CVE-2026-78676

·

Published

2026-08-10

·

Updated

2026-09-08

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.59
Description GitPython fails to safely re-serialize multi-line git-config values during write operations. This allows attackers to craft configuration files containing embedded newlines that can be corrupted into injected directives, such as core.hooksPath. When any unrelated configuration write occurs, these dormant quoted values become active git directives, which can lead to arbitrary code execution through hook invocation.
Recommendations Update GitPython to version 3.1.59 or later.

Exploit

Fix

RCE

Code Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12705
CVE-2026-78676
GHSA-284H-M62Q-GF8W
GHSA-9557-234J-7RV9
OPENSUSE-SU-2026:11615-1
PYSEC-2026-3786

Affected Products

Gitpython
Red Os