Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-69097

Опубликовано: 03 авг. 2026
Источник: nvd
CVSS3: 7
EPSS Низкий

Описание

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

EPSS

Процентиль: 8%
0.00187
Низкий

7 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7
ubuntu
28 дней назад

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

CVSS3: 7
debian
28 дней назад

GitPython before 3.1.53 fails to properly escape section names in git ...

CVSS3: 7
github
28 дней назад

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

CVSS3: 7
fstec
около 1 месяца назад

Уязвимость модуля записи конфигурации Git библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 8%
0.00187
Низкий

7 High

CVSS3

Дефекты

CWE-74