VDB
CVE-2026-87817
CVE-2026-87817
PUBLISHED
CVSS 8.7 HIGH
Reported by VulnCheck · Published September 9, 2026
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
Risk Scores
CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gitpython-developers | GitPython | 0, 3.1.60 |
| gitpython_project | gitpython | 0, 0 |
| chainguard | awx | 0 |
| chainguard | nemo-rl-cuda-13.0 | 0 |
| gitpython-developers | GitPython | 3.1.60, 0, 3.1.60 |
Timeline
- Sep 9, 2026 CVE Published
- Sep 10, 2026 EPSS Score
- Sep 10, 2026 CVE Updated
- Sep 15, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 24, 2026 Distribution Patch
- Sep 24, 2026 Security Advisory
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 1, 2026 Distribution Patch
References
- GitHub Security Advisory (GHSA-239g-whfq-7xj9) vendor-advisory
- VulnCheck Advisory: GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation third-party-advisory