Количество 9
Количество 9
CVE-2026-76221
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.
CVE-2026-76221
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.
CVE-2026-76221
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.
CVE-2026-76221
GitPython before 3.1.58 contains a config-name injection vulnerability ...
GHSA-78pq-g4m8-fx2c
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.
BDU:2026-12061
Уязвимость компонента валидации option-name validator библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды
ROS-20260901-80-0022
Уязвимость GitPython
ROS-20260901-73-0017
Уязвимость GitPython
SUSE-SU-2026:4072-1
Security update for python-GitPython
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-76221 GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. | CVSS3: 8.8 | 0% Низкий | 30 дней назад | |
CVE-2026-76221 GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. | CVSS3: 8.8 | 0% Низкий | 30 дней назад | |
CVE-2026-76221 GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. | CVSS3: 8.8 | 0% Низкий | 30 дней назад | |
CVE-2026-76221 GitPython before 3.1.58 contains a config-name injection vulnerability ... | CVSS3: 8.8 | 0% Низкий | 30 дней назад | |
GHSA-78pq-g4m8-fx2c GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. | CVSS3: 8.8 | 0% Низкий | 29 дней назад | |
BDU:2026-12061 Уязвимость компонента валидации option-name validator библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.8 | 0% Низкий | около 2 месяцев назад | |
ROS-20260901-80-0022 Уязвимость GitPython | CVSS3: 8.8 | 0% Низкий | 17 дней назад | |
ROS-20260901-73-0017 Уязвимость GitPython | CVSS3: 8.8 | 0% Низкий | 17 дней назад | |
SUSE-SU-2026:4072-1 Security update for python-GitPython | 10 дней назад |
Уязвимостей на страницу