Arbitrary Argument Injection Affecting gitpython package, versions [,3.1.59)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.4% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-GITPYTHON-19256804
  • published25 Aug 2026
  • disclosed25 Aug 2026
  • creditPig-Tail

Introduced: 25 Aug 2026

NewCVE-2026-78676  (opens in a new tab)
CWE-88  (opens in a new tab)

How to fix?

Upgrade GitPython to version 3.1.59 or higher.

Overview

GitPython is a python library used to interact with Git repositories

Affected versions of this package are vulnerable to Arbitrary Argument Injection via the write_section() serialization path in git/config.py. An attacker can create a dormant multi-line value in a Git config file and trigger arbitrary code execution by causing GitPython to perform any unrelated config write, which rewrites the embedded newline as a new directive such as core.hooksPath. When the affected repo is later processed by a hook-triggering Git operation, the injected core.hooksPath is honored as a real Git setting, letting attacker-controlled hook code run and giving the attacker code execution on the host.

CVSS Base Scores

version 4.0
version 3.1