{"id":"CVE-2026-42215","title":"GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215)","summary":"A flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows an attacker to achieve arbitrary command execution by providing specially crafted arguments (kwargs) to functions such as Rep…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-88","vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","affected":["exploit_intelligence","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","satellite 6","ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_19_for_rhel 9","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","openshift_ai 2.25","openshift_ai 3.4","satellite 6.18","satellite 6.19"],"patched":["ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_19_for_rhel 9","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","openshift_ai 2.25","openshift_ai 3.4","satellite 6.18","satellite 6.19"],"published":"2026-05-07","updated":"2026-09-24","sourceUpdated":"2026-09-24T05:59:06+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42215.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42215.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-42215"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2467802"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-42215"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42215"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4"},{"url":"https://access.redhat.com/errata/RHSA-2026:42078"},{"url":"https://access.redhat.com/errata/RHSA-2026:42079"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:71210"},{"url":"https://access.redhat.com/errata/RHSA-2026:71179"},{"url":"https://access.redhat.com/errata/RHSA-2026:42132"},{"url":"https://access.redhat.com/errata/RHSA-2026:67279"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:68764"},{"url":"https://access.redhat.com/errata/RHSA-2026:68771"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"},{"url":"https://access.redhat.com/errata/RHSA-2026:68776"},{"url":"https://github.com/gitpython-developers/GitPython"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00749,"epssPercentile":0.53458,"aliases":["GHSA-rpm5-65cw-6hj4","PYSEC-2026-2160"],"ecosystem":"pip","scores":{"vendor":7.5,"osv":8.8},"ingestedAt":"2026-07-13T18:58:02.847Z","slug":"CVE-2026-42215","body":"## Overview\n\nA flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows an attacker to achieve arbitrary command execution by providing specially crafted arguments (kwargs) to functions such as Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(). This bypasses existing security checks designed to block dangerous Git options, enabling the execution of unauthorized commands.\n\n## Vendor advisories\n\n- **RHSA-2026:42078** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42078)\n- **RHSA-2026:42079** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42079)\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)\n- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)\n- **RHSA-2026:42132** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42132)\n- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)\n- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)\n- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)\n- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)\n- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6 · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42215.json)\n- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)\n- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)\n\n**GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks** — rated Important by Red Hat. Released 2026-05-07, updated 2026-09-24.\n\nAffected:\n\n- Exploit Intelligence\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Ansible Automation Platform 2.5\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n- Red Hat Satellite 6.18\n- Red Hat Satellite 6.19\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Exploit Intelligence\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Ansible Automation Platform 2.5\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n\n## Remediation\n\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:42078\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:42079\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor detailed instructions how to apply this update, refer to:\n\nhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-42215)\n\nAffected packages:\n\n- `gitpython >= 3.1.30, < 3.1.47`\n\nPatched in:\n\n- `gitpython 3.1.47`\n\nSource: https://osv.dev/vulnerability/GHSA-rpm5-65cw-6hj4","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208480,"id":"CVE-2026-42215","ts":1790005715438,"field":"cvss","old":"8.8","new":"7.5"},{"seq":201637,"id":"CVE-2026-42215","ts":1789399580277,"field":"cvss","old":"7.5","new":"8.8"},{"seq":200369,"id":"CVE-2026-42215","ts":1789397173632,"field":"cvss","old":"8.8","new":"7.5"},{"seq":198293,"id":"CVE-2026-42215","ts":1789391803509,"field":"cvss","old":"7.5","new":"8.8"},{"seq":196086,"id":"CVE-2026-42215","ts":1789383452706,"field":"cvss","old":"8.8","new":"7.5"},{"seq":195015,"id":"CVE-2026-42215","ts":1789380347740,"field":"cvss","old":"7.5","new":"8.8"},{"seq":193802,"id":"CVE-2026-42215","ts":1789378318794,"field":"cvss","old":"8.8","new":"7.5"},{"seq":192589,"id":"CVE-2026-42215","ts":1789376293203,"field":"cvss","old":"7.5","new":"8.8"},{"seq":191376,"id":"CVE-2026-42215","ts":1789373204849,"field":"cvss","old":"8.8","new":"7.5"},{"seq":190161,"id":"CVE-2026-42215","ts":1789369185661,"field":"cvss","old":"7.5","new":"8.8"},{"seq":188948,"id":"CVE-2026-42215","ts":1789368068135,"field":"cvss","old":"8.8","new":"7.5"},{"seq":187731,"id":"CVE-2026-42215","ts":1789365042472,"field":"cvss","old":"7.5","new":"8.8"},{"seq":186518,"id":"CVE-2026-42215","ts":1789363060429,"field":"cvss","old":"8.8","new":"7.5"},{"seq":185304,"id":"CVE-2026-42215","ts":1789361000105,"field":"cvss","old":"7.5","new":"8.8"},{"seq":184091,"id":"CVE-2026-42215","ts":1789357990962,"field":"cvss","old":"8.8","new":"7.5"},{"seq":182343,"id":"CVE-2026-42215","ts":1789354139301,"field":"cvss","old":"7.5","new":"8.8"},{"seq":181136,"id":"CVE-2026-42215","ts":1789352987436,"field":"cvss","old":"8.8","new":"7.5"},{"seq":179929,"id":"CVE-2026-42215","ts":1789350050424,"field":"cvss","old":"7.5","new":"8.8"},{"seq":178722,"id":"CVE-2026-42215","ts":1789347903453,"field":"cvss","old":"8.8","new":"7.5"},{"seq":177515,"id":"CVE-2026-42215","ts":1789346204609,"field":"cvss","old":"7.5","new":"8.8"},{"seq":176308,"id":"CVE-2026-42215","ts":1789342806672,"field":"cvss","old":"8.8","new":"7.5"},{"seq":175762,"id":"CVE-2026-42215","ts":1789338593402,"field":"cvss","old":"7.5","new":"8.8"},{"seq":175632,"id":"CVE-2026-42215","ts":1789338431334,"field":"cvss","old":"8.8","new":"7.5"},{"seq":174427,"id":"CVE-2026-42215","ts":1789334637628,"field":"cvss","old":"7.5","new":"8.8"},{"seq":173222,"id":"CVE-2026-42215","ts":1789333301258,"field":"cvss","old":"8.8","new":"7.5"},{"seq":172036,"id":"CVE-2026-42215","ts":1789330923693,"field":"cvss","old":"7.5","new":"8.8"},{"seq":170850,"id":"CVE-2026-42215","ts":1789328430074,"field":"cvss","old":"8.8","new":"7.5"},{"seq":169645,"id":"CVE-2026-42215","ts":1789326947689,"field":"cvss","old":"7.5","new":"8.8"},{"seq":168440,"id":"CVE-2026-42215","ts":1789323500588,"field":"cvss","old":"8.8","new":"7.5"},{"seq":167235,"id":"CVE-2026-42215","ts":1789319409185,"field":"cvss","old":"7.5","new":"8.8"},{"seq":166030,"id":"CVE-2026-42215","ts":1789318358633,"field":"cvss","old":"8.8","new":"7.5"},{"seq":164825,"id":"CVE-2026-42215","ts":1789315583810,"field":"cvss","old":"7.5","new":"8.8"},{"seq":163620,"id":"CVE-2026-42215","ts":1789313298868,"field":"cvss","old":"8.8","new":"7.5"},{"seq":162415,"id":"CVE-2026-42215","ts":1789311737214,"field":"cvss","old":"7.5","new":"8.8"},{"seq":161210,"id":"CVE-2026-42215","ts":1789308320984,"field":"cvss","old":"8.8","new":"7.5"},{"seq":160715,"id":"CVE-2026-42215","ts":1789304248833,"field":"cvss","old":"7.5","new":"8.8"},{"seq":158553,"id":"CVE-2026-42215","ts":1789299338497,"field":"cvss","old":"8.8","new":"7.5"},{"seq":157517,"id":"CVE-2026-42215","ts":1789296489691,"field":"cvss","old":"7.5","new":"8.8"},{"seq":156312,"id":"CVE-2026-42215","ts":1789294427951,"field":"cvss","old":"8.8","new":"7.5"},{"seq":155107,"id":"CVE-2026-42215","ts":1789292685413,"field":"cvss","old":"7.5","new":"8.8"},{"seq":153902,"id":"CVE-2026-42215","ts":1789289411431,"field":"cvss","old":"8.8","new":"7.5"},{"seq":152552,"id":"CVE-2026-42215","ts":1789281296696,"field":"cvss","old":"7.5","new":"8.8"},{"seq":148048,"id":"CVE-2026-42215","ts":1789270923028,"field":"cvss","old":"8.8","new":"7.5"},{"seq":146088,"id":"CVE-2026-42215","ts":1789269198649,"field":"cvss","old":"7.5","new":"8.8"},{"seq":144991,"id":"CVE-2026-42215","ts":1789266155807,"field":"cvss","old":"8.8","new":"7.5"},{"seq":143895,"id":"CVE-2026-42215","ts":1789262491551,"field":"cvss","old":"7.5","new":"8.8"},{"seq":142731,"id":"CVE-2026-42215","ts":1789261243294,"field":"cvss","old":"8.8","new":"7.5"},{"seq":141567,"id":"CVE-2026-42215","ts":1789258644658,"field":"cvss","old":"7.5","new":"8.8"},{"seq":140369,"id":"CVE-2026-42215","ts":1789256445735,"field":"cvss","old":"8.8","new":"7.5"},{"seq":139171,"id":"CVE-2026-42215","ts":1789254624907,"field":"cvss","old":"7.5","new":"8.8"}]}