Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-67324: GitPython 3.1.50 lets attackers run code when cloning
CVE-2026-67324 · published 1 month ago
Summary
The GitPython library version 3.1.50 fails to stop a special command option during a repository clone. An attacker could supply a crafted clone request that runs their own program on the system, creating a security risk. Upgrade to GitPython 3.1.51 or newer to protect against this.
What to do
- Update debian python-git to version 3.1.61-1.
- Update gitpython-developers gitpython to version 3.1.51 or later.
- Update gitpython_project gitpython to version 3.1.50 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:20.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:24.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | python-git | All versions |
| Debian:11 | debian | python-git | All versions |
| Debian:12 | debian | python-git | All versions |
| Debian:13 | debian | python-git | All versions |
| Debian:14 | debian | python-git |
< 3.1.61-1 Fix: upgrade to 3.1.61-1
|
| – | gitpython-developers | gitpython | < 3.1.51 |
| Ubuntu:Pro:14.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | python-git | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | python-git | All versions |
| – | gitpython_project | gitpython |
< 3.1.50 cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* |
Original advisory text
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes a...
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git to execute the specified helper command during clone. Fixed in 3.1.51.
References
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v396-... Exploit Vendor Advisory
- https://www.vulncheck.com/advisories/gitpython-authentication-bypass-via-joined-... Third Party Advisory
- https://ubuntu.com/security/CVE-2026-67324 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-67324 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-67324 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 4.0: 9.9 (OSV)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published1 Aug 2026
Updated27 Sep 2026
First seen1 Aug 2026
Sources
UBUNTU-CVE-2026-67324 · OSV
DEBIAN-CVE-2026-67324 · OSV
CVE-2026-67324 · NVD
CVE-2026-67324 · MITRE
Track software like this
Free during beta