Improper Validation of Specified Type of Input in GitPython - #VU152987
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper validation of specified input type in Git.ls_remote when processing a caller-supplied remote URL. A remote attacker can supply an ext:: remote-helper URL to execute arbitrary code.
Exploitation requires user interaction and a Git transport policy that permits the ext transport.