VDB

CVE-2026-87817

CVE-2026-87817 PUBLISHED CVSS 8.7 HIGH

Reported by VulnCheck · Published September 9, 2026

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

Risk Scores

CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
gitpython-developersGitPython0, 3.1.60
gitpython_projectgitpython0, 0
chainguardawx0
chainguardnemo-rl-cuda-13.00
gitpython-developersGitPython3.1.60, 0, 3.1.60

Timeline

  • Sep 9, 2026 CVE Published
  • Sep 10, 2026 EPSS Score
  • Sep 10, 2026 CVE Updated
  • Sep 15, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 24, 2026 Distribution Patch
  • Sep 24, 2026 Security Advisory
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 1, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›