GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 02 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* |
Thu, 27 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation. | |
| Title | GitPython before 3.1.59 Remote Code Execution via Config Injection | |
| First Time appeared |
Gitpython Project
Gitpython Project gitpython |
|
| Weaknesses | CWE-88 | |
| CPEs | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitpython Project
Gitpython Project gitpython |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-25T01:30:33.754Z
Updated: 2026-08-26T16:12:27.979Z
Reserved: 2026-08-25T01:17:12.262Z
Link: CVE-2026-78676
Updated: 2026-08-26T16:08:07.046Z
Status : Analyzed
Published: 2026-08-25T02:16:52.030
Modified: 2026-09-02T19:13:44.823
Link: CVE-2026-78676