PT-2026-99360 · Pypi · Gitpython

·

CVE-2026-100689

·

Published

2026-09-26

·

Updated

2026-10-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.62
Description GitPython fails to validate the path field read from an untrusted .gitmodules file during submodule updates. While constraints exist for the name field and certain operations like add and move, the update() function derives the absolute checkout location from the raw path value without proper guards. An attacker can use directory traversal components in the path field to cause the creation of directories outside the repository working tree via os.makedirs(), populate them from the submodule URL, or remove them using shutil.rmtree() when force remove is enabled. This issue is exploitable in application flows that update submodules at a non-HEAD commit, such as a historical-commit API.
Recommendations Update GitPython to version 3.1.62.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100689
GHSA-59CR-6R3X-644W
OPENSUSE-SU-2026:11971-1

Affected Products

Gitpython