VDB
CVE-2026-78676
CVE-2026-78676
PUBLISHED
CVSS 9.3 CRITICAL
Reported by VulnCheck · Published August 25, 2026
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
Risk Scores
CVSS 4.0
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gitpython-developers | GitPython | 0, 3.1.59 |
| PyPI | GitPython | 0 |
| wolfi | mlflow | 0, 0, 0 |
| alpine | py3-gitpython | 0, 0, 0 |
| gitpython-developers | GitPython | 0, 3.1.59, 3.1.59 |
| chainguard | mlflow | 0, 0, 0 |
| gitpython_project | gitpython | 0, 0, 0 |
Timeline
- Aug 25, 2026 EPSS Score
- Aug 25, 2026 CVE Published
- Aug 27, 2026 EPSS Score
- Sep 1, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 3, 2026 Security Advisory
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-284h-m62q-gf8w) vendor-advisory
- VulnCheck Advisory: GitPython before 3.1.59 Remote Code Execution via Config Injection third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-78676 advisory
- https://github.com/advisories/GHSA-284h-m62q-gf8w advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml advisory