SB2026093094 - openEuler 24.03 LTS SP1 update for python-GitPython



SB2026093094 - openEuler 24.03 LTS SP1 update for python-GitPython

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093094
CSH Severity
High
Patch available
YES
Number of vulnerabilities 17
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 12% Medium 47% Low 41%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 17 vulnerabilities.


1) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-76218)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of argument delimiters in Repo.init when forwarding user-supplied git options to git init. A remote user can supply a crafted template option to plant a hook that executes on the next git operation to execute arbitrary code.

Exploitation requires the application to pass an attacker-controlled template argument and for an executable hook directory to be staged at a known path.


2) Argument injection (CVE-ID: CVE-2026-78679)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of argument delimiters in TagReference.create() when forwarding a caller-influenced positional reference value to git tag. A remote user can supply a reference value containing a --file option to disclose sensitive information.

Exploitation requires an embedding application to forward a caller-influenced reference value to TagReference.create().


3) Path traversal (CVE-ID: CVE-2026-78677)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to create an arbitrary git directory outside the intended destination.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in Repo.clone_from()/Repo.clone() option handling when forwarding a caller-controlled separate_git_dir argument to git clone. A remote attacker can supply a specially crafted separate_git_dir path to create an arbitrary git directory outside the intended destination.

Exploitation requires a host application to pass attacker-influenced clone options to the API without rejecting the separate_git_dir argument.


4) Code Injection (CVE-ID: CVE-2026-78676)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to code injection in GitConfigParser._write()/write_section() in git/config.py when re-serializing previously parsed multi-line git-config values during an unrelated config write. A remote attacker can supply a crafted config value that is rewritten into a live injected directive such as core.hooksPath to execute arbitrary code.

Exploitation requires an attacker-influenced config file to be opened read-write and later flushed through any legitimate write operation. The injected directive becomes active on a subsequent hook-firing git operation.


5) External Control of File Name or Path (CVE-ID: CVE-2026-78675)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information from arbitrary local files.

The vulnerability exists due to external control of file name or path in SubmoduleConfigParser and GitConfigParser when parsing an untrusted .gitmodules file containing an [include] directive. A remote attacker can supply a crafted repository whose .gitmodules references a readable local file to disclose sensitive information from arbitrary local files.

The disclosure occurs through an uncaught parsing exception that embeds the first line of the referenced file in the error message during submodule enumeration.


6) Path traversal (CVE-ID: CVE-2026-76222)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to create arbitrary Git repositories outside the working tree.

The vulnerability exists due to path traversal in submodule initialization logic when processing a cloned repository's .gitmodules submodule name during submodule initialization. A remote attacker can supply a specially crafted repository with a traversal string in the submodule name to create arbitrary Git repositories outside the working tree.

User interaction is required to clone the malicious repository and run submodule initialization.


7) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-76221)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in the GitPython config writer when writing attacker-controlled option names into git configuration files. A remote user can supply a crafted option name to forge git configuration directives and execute arbitrary code.

Exploitation requires an embedding application to pass a caller-influenced option name to the configuration writer, and code execution occurs on a subsequent git operation such as an ssh git action or hook execution.


8) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-76220)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary commands.

The vulnerability exists due to improper neutralization of argument delimiters in a command in the unsafe option guard for git kwargs handling when processing user-controlled keyword arguments with split_single_char_options disabled. A remote user can supply a crafted single-character option value that is transformed into a joined short-option token to execute arbitrary commands.

Exploitation requires an application to forward a user-controlled kwargs dictionary to a guarded GitPython method such as clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive.


9) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-76219)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to overwrite arbitrary files.

The vulnerability exists due to improper neutralization of argument delimiters in a command in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree when appending caller-influenced treeish arguments to git read-tree. A remote user can supply a specially crafted treeish value to overwrite arbitrary files.

The overwritten content is constrained to a valid git index blob rather than attacker-chosen file contents.


10) External Control of File Name or Path (CVE-ID: CVE-2026-73619)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to external control of file name or path in Repo.archive() when processing caller-influenced archive options. A remote user can supply a crafted --add-file option to disclose sensitive information.

Exploitation requires an application to forward caller-influenced keyword arguments into Repo.archive().


11) Information disclosure (CVE-ID: CVE-2026-76217)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in IndexFile.remove() and Head.checkout() when forwarding user-supplied keyword arguments to git rm and git checkout. A remote user can supply a crafted pathspec_from_file value together with pathspec_file_nul to disclose sensitive information.

The targeted file must be readable by the process, and disclosure occurs in the returned GitCommandError stderr when the supplied pathspec does not match a tracked path.


12) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-73625)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary os commands.

The vulnerability exists due to improper neutralization of argument delimiters in a command in the check_unsafe_options guard and single-character kwarg transformation logic when processing user-supplied keyword arguments for guarded git methods. A remote user can supply a single-character kwarg value that is transformed into a separate unsafe git option token to execute arbitrary os commands.

In the default configuration, the issue affects guarded methods including clone, fetch, pull, push, ls_remote, iter_commits, blame, and archive.


13) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-73624)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to overwrite arbitrary files.

The vulnerability exists due to improper neutralization of argument delimiters in a command in Diffable.diff when forwarding user-controlled arguments to git diff or git diff-tree. A remote user can supply a crafted output argument or a crafted other value to overwrite arbitrary files.

The issue affects both key-controlled and value-controlled input paths because the caller-supplied other reference is inserted before the -- separator and can be parsed as a git option.


14) Incomplete List of Disallowed Inputs (CVE-ID: CVE-2026-73623)

CWE-ID: CWE-184 - Incomplete List of Disallowed Inputs

CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary commands.

The vulnerability exists due to an incomplete list of disallowed inputs in unsafe_git_clone_options in base.py when processing clone options. A remote user can supply the --template option pointing to a directory containing a crafted hook to execute arbitrary commands.

Exploitation requires an attacker-readable directory containing an executable hook, and the post-checkout hook is executed during clone.


15) Information disclosure (CVE-ID: CVE-2026-73622)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in Repo.create_remote(), Remote.add(), and Submodule.add() when processing an attacker-controlled repository URL. A remote attacker can supply a URL containing environment-variable references to disclose sensitive information.

The supplied variable references are expanded server-side, stored in .git/config, and the resulting secret-bearing URL is transmitted on the next fetch, pull, or remote update. In the Submodule.add() path, the expanded URL is also written to .gitmodules.


16) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-73621)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to truncate an arbitrary file.

The vulnerability exists due to improper neutralization of argument delimiters in a command in Commit.count when forwarding user-supplied keyword arguments to git rev-list. A remote user can supply a crafted output argument to truncate an arbitrary file.

The file is truncated to 0 bytes at the privilege level of the running process.


17) External Control of File Name or Path (CVE-ID: CVE-2026-73620)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to overwrite arbitrary files.

The vulnerability exists due to external control of file name or path in IndexFile.checkout() when forwarding user-supplied git options to git checkout-index. A remote user can supply a crafted prefix option to overwrite arbitrary files.

The written content is taken from repository-controlled tracked files, and the overwrite can occur outside the working tree.


Remediation

Install update from vendor's website.