Argument injection in GitPython - #VU152990
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper neutralization of argument delimiters in GitPython Remote.pull() when processing attacker-influenced refspec values. A remote attacker can supply an option-shaped refspec that bypasses the unsafe-option guard to execute arbitrary commands.
Exploitation requires a local filesystem path or SSH transport, where the supplied upload-pack program is executed on the local side.