CVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule name
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69097
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69097 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for GitPython
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-67326: GitPython before 3.1.50 fails to validate newline characters in the section parameter of confi…nvd · 2026-08-01
- highCVE-2026-67325: GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to accou…nvd · 2026-08-01
- criticalCVE-2026-67324: GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --…nvd · 2026-08-01
- highCVE-2026-67323: GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword argumen…nvd · 2026-08-01
- highCVE-2026-67322: GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(…nvd · 2026-08-01
- highGHSA-94p4-4cq8-9g67: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL …ghsa · 2026-07-24
More from NVD Recent CVEs
- unknownCVE-2026-9487: XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_x…2026-08-03
- unknownCVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_si…2026-08-03
- highCVE-2026-69096: OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docke…2026-08-03
- highCVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path t…2026-08-03
- mediumCVE-2026-69094: Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_t…2026-08-03