Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78676

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

Отчет

Case for AC:H (8.1): the trigger needs two things the attacker does not straightforwardly own: (1) a crafted multi-line quoted value must already sit DORMANT in .git/config — the guarded set_value() path will not put it there; it must arrive via _read() of a file the attacker influenced but does not directly write; and (2) a SUBSEQUENT, UNRELATED GitPython config WRITE must fire to re-serialize and corrupt it — and that write is performed by the victim application on its own schedule, not by the attacker. "Prepare the target environment" + "conditions beyond the attacker's control" is the textbook AC:H definition; step (2) in particular fits it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Exploit Intelligenceexploit-intelligence/vulnerability-analysis-rhel9Affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2523197gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection

EPSS

Процентиль: 36%
0.00426
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
nvd
24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
debian
24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-co ...

CVSS3: 9.8
github
9 дней назад

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

CVSS3: 9.8
fstec
около 1 месяца назад

Уязвимость функции GitConfigParser._read() модуля git/config.py библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 36%
0.00426
Низкий

9.8 Critical

CVSS3