CRITICAL 9.3 NVD

CVE-2026-78676

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected direct

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

References

Published: 2026-08-25 · Source: NVD · Feed updated: 2026-08-25
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-25 via NVD.

Risk Timeline

CVE Disclosed2026-08-25 · -1 days ago

Remediation Resources

vulnfeed aggregates 11266 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.