SB2026093092 - Multiple vulnerabilities in GitPython



SB2026093092 - Multiple vulnerabilities in GitPython

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093092
CSH Severity
High
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 20% Medium 20% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) External Control of File Name or Path (CVE-ID: CVE-2026-78675)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information from arbitrary local files.

The vulnerability exists due to external control of file name or path in SubmoduleConfigParser and GitConfigParser when parsing an untrusted .gitmodules file containing an [include] directive. A remote attacker can supply a crafted repository whose .gitmodules references a readable local file to disclose sensitive information from arbitrary local files.

The disclosure occurs through an uncaught parsing exception that embeds the first line of the referenced file in the error message during submodule enumeration.


2) Code Injection (CVE-ID: CVE-2026-78676)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to code injection in GitConfigParser._write()/write_section() in git/config.py when re-serializing previously parsed multi-line git-config values during an unrelated config write. A remote attacker can supply a crafted config value that is rewritten into a live injected directive such as core.hooksPath to execute arbitrary code.

Exploitation requires an attacker-influenced config file to be opened read-write and later flushed through any legitimate write operation. The injected directive becomes active on a subsequent hook-firing git operation.


3) Path traversal (CVE-ID: CVE-2026-78677)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to create an arbitrary git directory outside the intended destination.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in Repo.clone_from()/Repo.clone() option handling when forwarding a caller-controlled separate_git_dir argument to git clone. A remote attacker can supply a specially crafted separate_git_dir path to create an arbitrary git directory outside the intended destination.

Exploitation requires a host application to pass attacker-influenced clone options to the API without rejecting the separate_git_dir argument.


4) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-78678)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of argument delimiters in Repo.blame() and Repo.blame_incremental() when processing a caller-influenced revision value. A remote user can pass a specially crafted revision option such as --contents=<path> or -S <file> to disclose sensitive information.

The file contents are echoed into the blame result returned to the caller, and the issue occurs with the default allow_unsafe_options=false setting.


5) Argument injection (CVE-ID: CVE-2026-78679)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of argument delimiters in TagReference.create() when forwarding a caller-influenced positional reference value to git tag. A remote user can supply a reference value containing a --file option to disclose sensitive information.

Exploitation requires an embedding application to forward a caller-influenced reference value to TagReference.create().


Remediation

Install update from vendor's website.