Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-78676

Опубликовано: 25 авг. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
Версия до 3.1.59 (исключая)

EPSS

Процентиль: 36%
0.00426
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 9.8
ubuntu
24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
redhat
24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
debian
24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-co ...

CVSS3: 9.8
github
9 дней назад

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

CVSS3: 9.8
fstec
около 1 месяца назад

Уязвимость функции GitConfigParser._read() модуля git/config.py библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 36%
0.00426
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-88