Argument injection in GitPython - #VU152991
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper neutralization of argument delimiters in Head.checkout() when an application clones an attacker-controlled repository and checks out its default branch. A remote attacker can provide a repository whose default branch name is interpreted as a Git option to disclose sensitive information.
The target file must be readable by the application's process, and its absolute path must be known.