Argument injection in GitPython - #VU152991

 

Argument injection in GitPython - #VU152991

Published: September 30, 2026


Vulnerability identifier: #VU152991
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper neutralization of argument delimiters in Head.checkout() when an application clones an attacker-controlled repository and checks out its default branch. A remote attacker can provide a repository whose default branch name is interpreted as a Git option to disclose sensitive information.

The target file must be readable by the application's process, and its absolute path must be known.


Affected software

GitPython

Remediation

Install security update from vendor's website.

GitPython - update to 3.2.0

External References

Related Security Bulletins