Insecure DLL loading in GitPython - #VU145797
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in Repo._config_reader and git directory resolution when opening a crafted repository and reading repository configuration. A remote attacker can provide a crafted config with include directives to disclose sensitive information.
User interaction is required to open or clone the crafted repository.