Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-44244

3 месяца назад

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path. This issue has been patched in version 3.1.49.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-44244

3 месяца назад

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path. This issue has been patched in version 3.1.49.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-44244

3 месяца назад

GitPython is a python library used to interact with Git repositories. ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260713-73-0048

20 дней назад

Уязвимость GitPython

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-v87r-6q3f-2j67

3 месяца назад

GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20777-1

3 месяца назад

Security update for python-GitPython

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-44244

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path. This issue has been patched in version 3.1.49.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44244

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path. This issue has been patched in version 3.1.49.

CVSS3: 7.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-44244

GitPython is a python library used to interact with Git repositories. ...

CVSS3: 7.8
0%
Низкий
3 месяца назад
redos логотип
ROS-20260713-73-0048

Уязвимость GitPython

CVSS3: 7.8
0%
Низкий
20 дней назад
github логотип
GHSA-v87r-6q3f-2j67

GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

CVSS3: 7.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20777-1

Security update for python-GitPython

3 месяца назад

Уязвимостей на страницу