| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-284h-m62q-gf8w | GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 04 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 02 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* |
Thu, 27 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation. | |
| Title | GitPython before 3.1.59 Remote Code Execution via Config Injection | |
| First Time appeared |
Gitpython Project
Gitpython Project gitpython |
|
| Weaknesses | CWE-88 | |
| CPEs | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitpython Project
Gitpython Project gitpython |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-26T16:12:27.979Z
Reserved: 2026-08-25T01:17:12.262Z
Link: CVE-2026-78676
Updated: 2026-08-26T16:08:07.046Z
Status : Analyzed
Published: 2026-08-25T02:16:52.030
Modified: 2026-09-02T19:13:44.823
Link: CVE-2026-78676
OpenCVE Enrichment
Updated: 2026-08-25T05:00:10Z
Github GHSA