VDB

CVE-2026-78676

CVE-2026-78676 PUBLISHED CVSS 9.3 CRITICAL

Reported by VulnCheck · Published August 25, 2026

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

Risk Scores

CVSS 4.0
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
gitpython-developersGitPython0, 3.1.59
PyPIGitPython0
wolfimlflow0, 0, 0
alpinepy3-gitpython0, 0, 0
gitpython-developersGitPython0, 3.1.59, 3.1.59
chainguardmlflow0, 0, 0
gitpython_projectgitpython0, 0, 0

Timeline

  • Aug 25, 2026 EPSS Score
  • Aug 25, 2026 CVE Published
  • Aug 27, 2026 EPSS Score
  • Sep 1, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 3, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›