VDB

CVE-2026-76222

CVE-2026-76222 PUBLISHED CVSS 8.4 HIGH

Reported by VulnCheck · Published August 19, 2026

GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.

Risk Scores

CVSS 4.0
8.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L

Affected Products

VendorProductVersions
gitpython-developersGitPython0, 3.1.58
gitpython-developersGitPython3.1.58, 0, 3.1.58
chainguardcheckov0, 0
alpinepy3-gitpython0, 0, 0
gitpython_projectgitpython0, 0
wolficheckov0, 0, 0
chainguardawx0, 0
chainguardmlflow0
wolfimlflow0, 0, 0
chainguardopal0, 0

Timeline

  • Aug 7, 2026 CVE Published
  • Aug 20, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Aug 28, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 4, 2026 Security Advisory
  • Sep 4, 2026 Distribution Patch
  • Sep 4, 2026 Security Advisory
  • Sep 8, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›