Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. GitPython
  4. ›
  5. CVE-2026-87817

CVE-2026-87817: GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution

September 30, 2026

Repo.__init__ decides which directory is the git directory by testing candidate paths in an order that considers the real .git last. Two earlier tests can be satisfied by ordinary tracked files. Git reserves only the literal name .git, so HEAD, objects/, refs/, config, gitdir, commondir and hooks/ at a repository root are all legal tracked content.

Consequently, after a victim opens or clones an attacker’s repository, GitPython resolves git_dir to the working-tree root while real git correctly resolves <root>/.git. Everything GitPython then treats as “inside the git directory” is attacker-authored content — including hooks/, which it executes.

References

  • github.com/advisories/GHSA-239g-whfq-7xj9
  • github.com/gitpython-developers/GitPython/commit/c7cf4d13b1ed0a2e70f2a1f3c6b4fc6c2652cf0b
  • github.com/gitpython-developers/GitPython/pull/2218
  • github.com/gitpython-developers/GitPython/releases/tag/3.1.60
  • github.com/gitpython-developers/GitPython/security/advisories/GHSA-239g-whfq-7xj9
  • github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3982.yaml
  • nvd.nist.gov/vuln/detail/CVE-2026-87817
  • www.vulncheck.com/advisories/gitpython-before-3.1.60-remote-code-execution-via-git-directory-impersonation

Code Behaviors & Features

Detect and mitigate CVE-2026-87817 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.1.60

Fixed versions

  • 3.1.60

Solution

Upgrade to version 3.1.60 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-427: Uncontrolled Search Path Element
  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

pypi/GitPython/CVE-2026-87817.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 01 Oct 2026 00:19:17 +0000.