PT-2026-81151 · Pypi+1 · Gitpython+1
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.59
Description
GitPython fails to safely re-serialize multi-line git-config values during write operations. This allows attackers to craft configuration files containing embedded newlines that can be corrupted into injected directives, such as
core.hooksPath. When any unrelated configuration write occurs, these dormant quoted values become active git directives, which can lead to arbitrary code execution through hook invocation.Recommendations
Update GitPython to version 3.1.59 or later.
Exploit
Fix
RCE
Code Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os