Improper Control of Dynamically-Identified Variables Affecting satellite-capsule:el8/python-gitpython package, versions *


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.28% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-SATELLITECAPSULE-18812144
  • published15 Aug 2026
  • disclosed13 Aug 2026

Introduced: 13 Aug 2026

NewCVE-2026-73622  (opens in a new tab)
CWE-914  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:10 satellite-capsule:el8/python-gitpython.

NVD Description

Note: Versions mentioned in the description apply only to the upstream satellite-capsule:el8/python-gitpython package and not the satellite-capsule:el8/python-gitpython package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.

CVSS Base Scores

version 3.1