Insecure DLL loading in GitPython - #VU145798
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite files in an attacker-chosen directory.
The vulnerability exists due to improper path resolution in commondir handling when processing a crafted repository layout. A remote attacker can provide an absolute tracked commondir value to overwrite files in an attacker-chosen directory.
User interaction is required to open or clone the crafted repository.