Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-78676

24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-78676

24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-78676

24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-78676

24 дня назад

GitPython before 3.1.59 fails to safely re-serialize multi-line git-co ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-284h-m62q-gf8w

9 дней назад

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2026-12705

около 1 месяца назад

Уязвимость функции GitConfigParser._read() модуля git/config.py библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20260908-80-0107

10 дней назад

Уязвимость GitPython

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20260908-73-0094

10 дней назад

Уязвимость GitPython

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4072-1

9 дней назад

Security update for python-GitPython

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-78676

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
0%
Низкий
24 дня назад
redhat логотип
CVE-2026-78676

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
0%
Низкий
24 дня назад
nvd логотип
CVE-2026-78676

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

CVSS3: 9.8
0%
Низкий
24 дня назад
debian логотип
CVE-2026-78676

GitPython before 3.1.59 fails to safely re-serialize multi-line git-co ...

CVSS3: 9.8
0%
Низкий
24 дня назад
github логотип
GHSA-284h-m62q-gf8w

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

CVSS3: 9.8
0%
Низкий
9 дней назад
fstec логотип
BDU:2026-12705

Уязвимость функции GitConfigParser._read() модуля git/config.py библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20260908-80-0107

Уязвимость GitPython

CVSS3: 9.8
0%
Низкий
10 дней назад
redos логотип
ROS-20260908-73-0094

Уязвимость GitPython

CVSS3: 9.8
0%
Низкий
10 дней назад
suse-cvrf логотип
SUSE-SU-2026:4072-1

Security update for python-GitPython

9 дней назад

Уязвимостей на страницу