Количество 5
Количество 5
CVE-2026-76221
(GitPython before 3.1.58 contains a config-name injection vulnerability ...)
CVE-2026-76221
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.
CVE-2026-76221
GitPython before 3.1.58 contains a config-name injection vulnerability ...
GHSA-78pq-g4m8-fx2c
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.
BDU:2026-12061
Уязвимость компонента валидации option-name validator библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection vulnerability ...) | CVSS3: 8.8 | 0% Низкий | 8 дней назад | |
CVE-2026-76221 GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. | CVSS3: 8.8 | 0% Низкий | 8 дней назад | |
CVE-2026-76221 GitPython before 3.1.58 contains a config-name injection vulnerability ... | CVSS3: 8.8 | 0% Низкий | 8 дней назад | |
GHSA-78pq-g4m8-fx2c GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation. | CVSS3: 8.8 | 0% Низкий | 8 дней назад | |
BDU:2026-12061 Уязвимость компонента валидации option-name validator библиотеки Python для взаимодействия с git-репозиториями GitPython, позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.8 | 0% Низкий | 24 дня назад |
Уязвимостей на страницу