CVE-2026-87817: GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
Repo.__init__ decides which directory is the git directory by testing candidate paths in an order that
considers the real .git last. Two earlier tests can be satisfied by ordinary tracked files. Git
reserves only the literal name .git, so HEAD, objects/, refs/, config, gitdir, commondir
and hooks/ at a repository root are all legal tracked content.
Consequently, after a victim opens or clones an attacker’s repository, GitPython resolves git_dir to
the working-tree root while real git correctly resolves <root>/.git. Everything GitPython then
treats as “inside the git directory” is attacker-authored content — including hooks/, which it
executes.
References
- github.com/advisories/GHSA-239g-whfq-7xj9
- github.com/gitpython-developers/GitPython/commit/c7cf4d13b1ed0a2e70f2a1f3c6b4fc6c2652cf0b
- github.com/gitpython-developers/GitPython/pull/2218
- github.com/gitpython-developers/GitPython/releases/tag/3.1.60
- github.com/gitpython-developers/GitPython/security/advisories/GHSA-239g-whfq-7xj9
- github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3982.yaml
- nvd.nist.gov/vuln/detail/CVE-2026-87817
- www.vulncheck.com/advisories/gitpython-before-3.1.60-remote-code-execution-via-git-directory-impersonation
Code Behaviors & Features
Detect and mitigate CVE-2026-87817 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →