Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73623

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

A flaw was found in GitPython. An incomplete denylist in the unsafe_git_clone_options function fails to restrict the --template option. This allows a remote attacker to supply a malicious Git template directory, leading to arbitrary command execution during clone operations.

Отчет

This is an Important severity flaw in GitPython where an incomplete denylist in unsafe_git_clone_options allows remote code execution. An attacker can leverage the --template option to execute arbitrary commands during repository cloning by pointing to a directory containing malicious post-checkout hooks. This risk is present when applications using GitPython clone untrusted repositories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2515275gitpython: GitPython: Remote Code Execution via malicious Git template

EPSS

Процентиль: 50%
0.00693
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
16 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

CVSS3: 7.5
nvd
16 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

CVSS3: 7.5
debian
16 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_ ...

CVSS3: 7.5
github
16 дней назад

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 50%
0.00693
Низкий

7.5 High

CVSS3