Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76219

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.

A flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the git read-tree command through methods like IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree, without proper option validation or argument separation, an attacker can cause the application to write a git-index blob to any attacker-controlled writable path, leading to data destruction.

Отчет

GitPython's IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree append caller-influenced treeish strings to git read-tree without option validation or argument separation, letting an attacker who controls those arguments inject the --index-output option to overwrite arbitrary files at attacker-controlled writable paths (data destruction), fixed in 3.1.58. Red Hat products that bundle GitPython use it as an internal build/automation-time dependency and do not expose these IndexFile treeish arguments to adversary-controlled input; the vulnerable input cannot be controlled by an attacker in these products, so they are marked not affected. GitPython as shipped in Red Hat OpenStack Platform 16.2 and 17.1 contains the vulnerable library code and retains its affected determination.

Меры по смягчению последствий

Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into git read-tree is fixed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Exploit Intelligenceexploit-intelligence/vulnerability-analysis-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Not affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2519597gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection

EPSS

Процентиль: 23%
0.00299
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
29 дней назад

GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.

CVSS3: 8.1
nvd
29 дней назад

GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.

CVSS3: 8.1
debian
29 дней назад

GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...

CVSS3: 8.1
github
около 1 месяца назад

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

CVSS3: 8.1
fstec
около 1 месяца назад

Уязвимость методов IndexFile.from_tree, IndexFile.reset и IndexFile.merge_tree библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю перезаписать произвольные файлы

EPSS

Процентиль: 23%
0.00299
Низкий

8.1 High

CVSS3