SB2026093095 - Multiple vulnerabilities in GitPython



SB2026093095 - Multiple vulnerabilities in GitPython

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093095
CSH Severity
High
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 13% Medium 88%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Information disclosure (CVE-ID: N/A)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper neutralization of environment-variable expansion in Repo._clone() when initializing submodules from a cloned repository with a crafted .gitmodules submodule name. A remote attacker can cause environment variables to be expanded in the separate_git_dir path to disclose sensitive information.

User interaction is required to clone the malicious repository and initialize its submodules.


2) Inefficient regular expression complexity (CVE-ID: N/A)

CWE-ID: CWE-1333 - Inefficient Regular Expression Complexity

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient regular expression complexity in the _re_actor_epoch regular expression used by parse_actor_and_date when processing malformed author, committer, or tagger lines in commit or tag objects. A remote attacker can supply a crafted commit or tag object to cause a denial of service.

Exploitation requires an application to read the affected actor field from an untrusted repository.


3) Improper Validation of Specified Type of Input (CVE-ID: N/A)

CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper validation of specified input type in Git.ls_remote when processing a caller-supplied remote URL. A remote attacker can supply an ext:: remote-helper URL to execute arbitrary code.

Exploitation requires user interaction and a Git transport policy that permits the ext transport.


4) Improper Validation of Specified Type of Input (CVE-ID: N/A)

CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject unsafe command-line options.

The vulnerability exists due to improper validation of specified input type in Repo.merge_base when forwarding caller-controlled revision arguments and keyword arguments to git merge-base. A remote attacker can supply unsafe keyword arguments to inject unsafe command-line options.

User interaction is required. Non-128 Git command errors are converted to an empty result.


5) Improper Validation of Specified Type of Input (CVE-ID: N/A)

CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject unsafe command-line options.

The vulnerability exists due to improper validation of specified input type in IndexFile.move when forwarding caller-controlled keyword arguments to git mv. A remote attacker can supply unsafe keyword arguments to inject unsafe command-line options.

User interaction is required.


6) Argument injection (CVE-ID: N/A)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to improper neutralization of argument delimiters in GitPython Remote.pull() when processing attacker-influenced refspec values. A remote attacker can supply an option-shaped refspec that bypasses the unsafe-option guard to execute arbitrary commands.

Exploitation requires a local filesystem path or SSH transport, where the supplied upload-pack program is executed on the local side.


7) Argument injection (CVE-ID: N/A)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper neutralization of argument delimiters in Head.checkout() when an application clones an attacker-controlled repository and checks out its default branch. A remote attacker can provide a repository whose default branch name is interpreted as a Git option to disclose sensitive information.

The target file must be readable by the application's process, and its absolute path must be known.


8) Link following (CVE-ID: N/A)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to move a submodule checkout outside the worktree and corrupt repository state.

The vulnerability exists due to improper link resolution before file access in Submodule.move() when processing a fixed move destination below an attacker-committed intermediate symbolic link. A remote attacker can commit a symbolic link in an untrusted repository to move an initialized submodule checkout to an external directory and corrupt repository state.

User interaction is required for an application to initialize the submodule and call Submodule.move() with the fixed destination. The issue applies where Git materializes tracked symbolic links as real symbolic links.


Remediation

Install update from vendor's website.