Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-67324: GitPython 3.1.50 lets attackers run code when cloning

CVE-2026-67324 · published 1 month ago
Summary

The GitPython library version 3.1.50 fails to stop a special command option during a repository clone. An attacker could supply a crafted clone request that runs their own program on the system, creating a security risk. Upgrade to GitPython 3.1.51 or newer to protect against this.

What to do
  • Update debian python-git to version 3.1.61-1.
  • Update gitpython-developers gitpython to version 3.1.51 or later.
  • Update gitpython_project gitpython to version 3.1.50 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:20.04:LTS canonical python-git All versions
Ubuntu:Pro:22.04:LTS canonical python-git All versions
Ubuntu:Pro:24.04:LTS canonical python-git All versions
Ubuntu:Pro:26.04:LTS canonical python-git All versions
Debian:11 debian python-git All versions
Debian:12 debian python-git All versions
Debian:13 debian python-git All versions
Debian:14 debian python-git < 3.1.61-1
Fix: upgrade to 3.1.61-1
– gitpython-developers gitpython < 3.1.51
Ubuntu:Pro:14.04:LTS canonical python-git All versions
Ubuntu:Pro:16.04:LTS canonical python-git All versions
Ubuntu:Pro:18.04:LTS canonical python-git All versions
– gitpython_project gitpython < 3.1.50
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
Original advisory text
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes a...
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 4.0: 9.9 (OSV)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published1 Aug 2026
Updated27 Sep 2026
First seen1 Aug 2026
Track software like this
Free during beta