{"id":"CVE-2026-76219","title":"gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219)","summary":"A flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, …","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cvssSource":"vendor","cwe":"CWE-88","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","affected":["ansible_automation_platform 2","satellite 6","satellite_6_19_for_rhel 9","satellite 6.18","satellite 6.19"],"patched":["satellite_6_19_for_rhel 9","satellite 6.18","satellite 6.19"],"published":"2026-08-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:27:40+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76219.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76219.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-76219"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2519597"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76219"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76219"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-read-tree"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:68764"},{"url":"https://access.redhat.com/errata/RHSA-2026:68771"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"},{"url":"https://access.redhat.com/errata/RHSA-2026:68776"},{"url":"https://github.com/gitpython-developers/GitPython/pull/2204"},{"url":"https://github.com/gitpython-developers/GitPython/commit/9b5dcaf85da5946dbf69dcd53f9edba08f760b32"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58"},{"url":"https://pypi.org/project/gitpython"},{"url":"https://github.com/advisories/GHSA-4gmw-gg2m-w46p"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00299,"epssPercentile":0.22737,"aliases":["GHSA-4gmw-gg2m-w46p","PYSEC-2026-3838"],"ecosystem":"pip","ingestedAt":"2026-08-20T19:23:04.841Z","slug":"CVE-2026-76219","body":"## Overview\n\nA flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, and `IndexFile.merge_tree`, without proper option validation or argument separation, an attacker can cause the application to write a git-index blob to any attacker-controlled writable path, leading to data destruction.\n\n## Vendor advisories\n\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)\n- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)\n- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)\n- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)\n- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2, Red Hat Satellite 6 · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Satellite 6 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76219.json)\n\n**gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection** — rated Important by Red Hat. Released 2026-08-19, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Satellite 6.18\n- Red Hat Satellite 6.19\n\nNo fix planned:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Satellite 6.19 for RHEL 9\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Pen Drive Powered by Red Hat Lightspeed\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Hardened Images\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor detailed instructions how to apply this update, refer to:\n\nhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68764\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68771\n\nWorkarounds / mitigations:\n\n- Do not pass untrusted or attacker-influenced treeish arguments to GitPython's IndexFile.from_tree, IndexFile.reset, or IndexFile.merge_tree. Upgrade to GitPython 3.1.58 or later, where option injection into `git read-tree` is fixed.\n\n## Package advisory (CVE-2026-76219)\n\nAffected packages:\n\n- `gitpython < 3.1.58`\n\nPatched in:\n\n- `gitpython 3.1.58`\n\nSource: https://osv.dev/vulnerability/GHSA-4gmw-gg2m-w46p","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}