PT-2026-81152 · Pypi+1 · Gitpython+1
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.59
Description
GitPython fails to include the
--separate-git-dir flag in its unsafe git clone options. This allows an attacker to provide a separate git dir parameter to the Repo.clone from() or Repo.clone() functions, redirecting repository metadata to an arbitrary filesystem path. This behavior can lead to the creation of unauthorized directories and the potential execution of git hooks, which are scripts that run automatically when certain events occur in a git repository.Recommendations
Update GitPython to version 3.1.59 or later.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython
Red Os