Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9xx9-hw38-h2w9

Опубликовано: 03 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.3
CVSS3: 7

Описание

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

EPSS

Процентиль: 8%
0.00187
Низкий

7.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7
ubuntu
28 дней назад

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

CVSS3: 7
nvd
28 дней назад

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

CVSS3: 7
debian
28 дней назад

GitPython before 3.1.53 fails to properly escape section names in git ...

CVSS3: 7
fstec
около 1 месяца назад

Уязвимость модуля записи конфигурации Git библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 8%
0.00187
Низкий

7.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-74