PT-2026-99360 · Pypi · Gitpython
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GitPython versions prior to 3.1.62
Description
GitPython fails to validate the
path field read from an untrusted .gitmodules file during submodule updates. While constraints exist for the name field and certain operations like add and move, the update() function derives the absolute checkout location from the raw path value without proper guards. An attacker can use directory traversal components in the path field to cause the creation of directories outside the repository working tree via os.makedirs(), populate them from the submodule URL, or remove them using shutil.rmtree() when force remove is enabled. This issue is exploitable in application flows that update submodules at a non-HEAD commit, such as a historical-commit API.Recommendations
Update GitPython to version 3.1.62.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitpython