PT-2026-81152 · Pypi+1 · Gitpython+1

·

CVE-2026-78677

·

Published

2026-08-10

·

Updated

2026-09-08

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.59
Description GitPython fails to include the --separate-git-dir flag in its unsafe git clone options. This allows an attacker to provide a separate git dir parameter to the Repo.clone from() or Repo.clone() functions, redirecting repository metadata to an arbitrary filesystem path. This behavior can lead to the creation of unauthorized directories and the potential execution of git hooks, which are scripts that run automatically when certain events occur in a git repository.
Recommendations Update GitPython to version 3.1.59 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12704
CVE-2026-78677
GHSA-7R39-6Q8M-QW68
GHSA-8MCC-HRX5-HVXC
PYSEC-2026-3787

Affected Products

Gitpython
Red Os