Argument injection in GitPython - CVE-2026-78679
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of argument delimiters in TagReference.create() when forwarding a caller-influenced positional reference value to git tag. A remote user can supply a reference value containing a --file option to disclose sensitive information.
Exploitation requires an embedding application to forward a caller-influenced reference value to TagReference.create().
Affected software
openEuler
python-GitPython
python-GitPython-help
python3-GitPython
How to mitigate CVE-2026-78679
python-GitPython - update to 3.1.59-1
python-GitPython-help - update to 3.1.59-1
python3-GitPython - update to 3.1.59-1