CRITICAL 9.3 NVD
CVE-2026-78676
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected direct
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
References
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w
- https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-inj
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-25 via NVD.
Risk Timeline
CVE Disclosed2026-08-25 · -1 days ago
Remediation Resources
vulnfeed aggregates 11266 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.