Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67324

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.

A flaw was found in GitPython. A remote attacker can exploit a vulnerability where the software fails to properly recognize joined short-option forms (e.g., -u) when enforcing its default unsafe-option gate. This allows the attacker to bypass security checks and execute arbitrary commands during a Git clone operation. This can lead to a complete compromise of the affected system.

Отчет

This vulnerability is rated as Important because exploitation requires an application to invoke Repo.clone_from() with attacker-controlled multi_options while allow_unsafe_options=False is set. This precondition means an attacker must already have some influence over a Git-related workflow within the consuming application, rather than exploiting it through mere network access. This affects GitPython version 3.1.50.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Not affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Not affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2510032gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass

EPSS

Процентиль: 31%
0.00379
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 месяца назад

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.

CVSS3: 9.8
nvd
около 1 месяца назад

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.

CVSS3: 9.8
debian
около 1 месяца назад

GitPython 3.1.50 fails to recognize joined short-option forms such as ...

CVSS3: 9.8
github
около 1 месяца назад

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость функции Repo.clone_from() библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 31%
0.00379
Низкий

8.8 High

CVSS3