Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76222

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal sequences. When GitPython processes these malicious submodule names during repository initialization, it could lead to the creation of attacker-controlled Git repositories at arbitrary locations on the filesystem, potentially impacting system integrity.

Отчет

CVE-2026-76222 is a path-traversal flaw in GitPython submodule handling: cloning a malicious repository and initializing its submodules can create files or repositories outside the intended directory, because GitPython omits the suspicious-submodule-name guard that upstream core git enforces. Unlike the caller-gated GitPython option-forwarding flaws, this triggers during ordinary clone plus submodule initialization of an untrusted repository, so any Red Hat product that ships or bundles a vulnerable GitPython version is affected. Fixed in GitPython 3.1.58.

Меры по смягчению последствий

There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Will not fix
Exploit Intelligenceexploit-intelligence/vulnerability-analysis-rhel9Affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2519609gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names

EPSS

Процентиль: 26%
0.00333
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
29 дней назад

GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.

CVSS3: 8.2
nvd
29 дней назад

GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.

CVSS3: 8.2
debian
29 дней назад

GitPython before 3.1.58 fails to validate submodule names from .gitmod ...

CVSS3: 8.2
github
около 1 месяца назад

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

CVSS3: 8.2
fstec
около 1 месяца назад

Уязвимость функции sm_name() файла src/GitPython/git/objects/submodule/util.py библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

EPSS

Процентиль: 26%
0.00333
Низкий

8.2 High

CVSS3