VDB
CVE-2026-76222
CVE-2026-76222
PUBLISHED
CVSS 8.4 HIGH
Reported by VulnCheck · Published August 19, 2026
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.
Risk Scores
CVSS 4.0
8.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gitpython-developers | GitPython | 0, 3.1.58 |
| gitpython-developers | GitPython | 3.1.58, 0, 3.1.58 |
| chainguard | checkov | 0, 0 |
| alpine | py3-gitpython | 0, 0, 0 |
| gitpython_project | gitpython | 0, 0 |
| wolfi | checkov | 0, 0, 0 |
| chainguard | awx | 0, 0 |
| chainguard | mlflow | 0 |
| wolfi | mlflow | 0, 0, 0 |
| chainguard | opal | 0, 0 |
Timeline
- Aug 7, 2026 CVE Published
- Aug 20, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 4, 2026 Security Advisory
- Sep 4, 2026 Distribution Patch
- Sep 4, 2026 Security Advisory
- Sep 8, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-hmq2-w58f-27jc) vendor-advisory
- VulnCheck Advisory: GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name third-party-advisory