Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87817

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

A flaw was found in GitPython. This vulnerability allows a remote attacker to execute arbitrary code. By failing to properly validate the git directory location, GitPython allows attackers to impersonate the git directory using tracked files such as gitdir, commondir, and HEAD. An attacker can then place a malicious pre-commit hook in the tracked hooks directory, which executes when a victim calls index.commit() on a cloned or opened repository.

Отчет

This vulnerability is rated as Important because it allows remote code execution in Red Hat products utilizing GitPython. Exploitation requires user interaction, specifically a victim calling index.commit() on a repository where an attacker has previously placed a malicious pre-commit hook by impersonating the git directory. This reduces the immediate threat compared to vulnerabilities exploitable without user interaction.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Exploit Intelligenceexploit-intelligence/vulnerability-analysis-rhel9Affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/controller-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/controller-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/hub-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2530744GitPython: GitPython: Remote Code Execution via Git directory impersonation

EPSS

Процентиль: 24%
0.00309
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
6 дней назад

(GitPython before 3.1.60 fails to properly validate the git directory l ...)

CVSS3: 8.8
nvd
7 дней назад

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

CVSS3: 8.8
debian
7 дней назад

GitPython before 3.1.60 fails to properly validate the git directory l ...

CVSS3: 8.8
github
7 дней назад

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

CVSS3: 8.8
fstec
21 день назад

Уязвимость библиотеки Python для взаимодействия с git-репозиториями GitPython, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 24%
0.00309
Низкий

8.8 High

CVSS3