Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-78676: GitPython may let attackers run code
CVE-2026-78676 · published 1 month ago
Summary
The GitPython library used in several Python packages can be exploited to execute unwanted code on your system. This affects the gitpython_project/gitpython, gitpython, debian/python-git, and gitpython-developers/gitpython packages. Update to the latest patched versions as soon as possible to protect your environment.
What to do
- Update gitpython to version 3.1.59.
- Update debian python-git to version 3.1.61-1.
- Update gitpython to version 3.1.46+aikido.13.
- Update gitpython to version 3.1.46+aikido.11.
- Update gitpython to version 3.1.58+aikido.1.
- Update gitpython_project gitpython to version 3.1.59 or later.
- Update gitpython-developers gitpython to version 3.1.59 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | gitpython_project | gitpython |
< 3.1.59 cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* |
| pip | – | gitpython |
<= 3.1.58 Fix: upgrade to 3.1.59
|
| Debian:14 | debian | python-git |
< 3.1.61-1 Fix: upgrade to 3.1.61-1
|
| – | gitpython-developers | gitpython | < 3.1.59 |
| Debian:11 | debian | python-git | All versions |
| Debian:12 | debian | python-git | All versions |
| Debian:13 | debian | python-git | All versions |
| Root:PyPI | – | gitpython |
< 3.1.46+aikido.13 < 3.1.46+aikido.11 Fix: upgrade to 3.1.46+aikido.13
|
| Root:PyPI | – | gitpython |
< 3.1.58+aikido.1 Fix: upgrade to 3.1.58+aikido.1
|
Original advisory text
CVE-2026-78676 in GitPython - Patched by Root
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
References
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-... Exploit Vendor Advisory Mitigation
- https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78676... Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-78676 Vendor Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3...
- https://github.com/advisories/GHSA-284h-m62q-gf8w
- https://nvd.nist.gov/vuln/detail/CVE-2026-78676
Severity
9.3
Critical
CVSS 3.1: 9.8 (OSV)
CVSS 3.1: 9.8 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CWE-94Code Injection
Timeline
Published25 Aug 2026
Updated29 Sep 2026
First seen25 Aug 2026
Sources
DEBIAN-CVE-2026-78676 · OSV
CVE-2026-78676 · NVD
CVE-2026-78676 · MITRE
CVE-2026-78676 · OSV
GHSA-284h-m62q-gf8w · GHSA
Track software like this
Free during beta