Link following in GitPython - #VU152992

 

Link following in GitPython - #VU152992

Published: September 30, 2026


Vulnerability identifier: #VU152992
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to move a submodule checkout outside the worktree and corrupt repository state.

The vulnerability exists due to improper link resolution before file access in Submodule.move() when processing a fixed move destination below an attacker-committed intermediate symbolic link. A remote attacker can commit a symbolic link in an untrusted repository to move an initialized submodule checkout to an external directory and corrupt repository state.

User interaction is required for an application to initialize the submodule and call Submodule.move() with the fixed destination. The issue applies where Git materializes tracked symbolic links as real symbolic links.


Affected software

GitPython

Remediation

Install security update from vendor's website.

GitPython - update to 3.2.0

External References

Related Security Bulletins