Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-78676: GitPython may let attackers run code

CVE-2026-78676 · published 1 month ago
Summary

The GitPython library used in several Python packages can be exploited to execute unwanted code on your system. This affects the gitpython_project/gitpython, gitpython, debian/python-git, and gitpython-developers/gitpython packages. Update to the latest patched versions as soon as possible to protect your environment.

What to do
  • Update gitpython to version 3.1.59.
  • Update debian python-git to version 3.1.61-1.
  • Update gitpython to version 3.1.46+aikido.13.
  • Update gitpython to version 3.1.46+aikido.11.
  • Update gitpython to version 3.1.58+aikido.1.
  • Update gitpython_project gitpython to version 3.1.59 or later.
  • Update gitpython-developers gitpython to version 3.1.59 or later.
Affected software
Ecosystem VendorProductAffected versions
– gitpython_project gitpython < 3.1.59
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
pip – gitpython <= 3.1.58
Fix: upgrade to 3.1.59
Debian:14 debian python-git < 3.1.61-1
Fix: upgrade to 3.1.61-1
– gitpython-developers gitpython < 3.1.59
Debian:11 debian python-git All versions
Debian:12 debian python-git All versions
Debian:13 debian python-git All versions
Root:PyPI – gitpython < 3.1.46+aikido.13
< 3.1.46+aikido.11
Fix: upgrade to 3.1.46+aikido.13
Root:PyPI – gitpython < 3.1.58+aikido.1
Fix: upgrade to 3.1.58+aikido.1
Original advisory text
CVE-2026-78676 in GitPython - Patched by Root
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
Severity
9.3 Critical
CVSS 3.1: 9.8 (OSV)
CVSS 3.1: 9.8 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CWE-94Code Injection
Timeline
Published25 Aug 2026
Updated29 Sep 2026
First seen25 Aug 2026
Track software like this
Free during beta