{"id":"CVE-2026-76221","title":"gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)","summary":"A flaw was found in GitPython. This vulnerability allows attackers to inject malicious configuration options by manipulating option names within the option-name validator. By injecting special characters, an attacker can forge arbitrary gi…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-78","vendor":"Red Hat","product":"Red Hat Satellite 6.19 for RHEL 9","affected":["ansible_automation_platform 2","satellite 6","satellite_6_19_for_rhel 9","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","satellite 6.18","satellite 6.19"],"patched":["satellite_6_19_for_rhel 9","ansible_automation_platform 2.5","ansible_automation_platform 2.6","ansible_automation_platform 2.7","satellite 6.18","satellite 6.19"],"published":"2026-08-19","updated":"2026-09-24","sourceUpdated":"2026-09-24T06:02:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76221.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76221.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-76221"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2519596"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76221"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76221"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgr"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-config-injection-via-option-name"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:71210"},{"url":"https://access.redhat.com/errata/RHSA-2026:71179"},{"url":"https://access.redhat.com/errata/RHSA-2026:71177"},{"url":"https://access.redhat.com/errata/RHSA-2026:68764"},{"url":"https://access.redhat.com/errata/RHSA-2026:68771"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"},{"url":"https://access.redhat.com/errata/RHSA-2026:68776"},{"url":"https://github.com/gitpython-developers/GitPython/pull/2204"},{"url":"https://github.com/gitpython-developers/GitPython/commit/a495ccd3b547ccd60b2187215823b72a9c0188bf"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00485,"epssPercentile":0.40895,"aliases":["GHSA-jm78-9fvv-mhgr","PYSEC-2026-3783"],"ecosystem":"pip","ingestedAt":"2026-08-20T19:23:06.371Z","slug":"CVE-2026-76221","body":"## Overview\n\nA flaw was found in GitPython. This vulnerability allows attackers to inject malicious configuration options by manipulating option names within the option-name validator. By injecting special characters, an attacker can forge arbitrary git-config directives, potentially leading to arbitrary code execution on the system when a git operation is performed.\n\n## Vendor advisories\n\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)\n- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)\n- **RHSA-2026:71177** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71177)\n- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)\n- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)\n- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)\n- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)\n- **Red Hat VEX** · Important · affected: Red Hat Ansible Automation Platform 2, Red Hat Satellite 6 · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Satellite 6 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76221.json)\n\n**gitpython: GitPython: Arbitrary code execution via config-name injection** — rated Important by Red Hat. Released 2026-08-19, updated 2026-09-24.\n\nAffected:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Ansible Automation Platform 2.5\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat Satellite 6.18\n- Red Hat Satellite 6.19\n\nNo fix planned:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Ansible Automation Platform 2.5\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Pen Drive Powered by Red Hat Lightspeed\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor detailed instructions how to apply this update, refer to:\n\nhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\nFor details on how to apply this update, refer to:\nhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading https://access.redhat.com/errata/RHSA-2026:71210\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\nFor details on how to apply this update, refer to:\nhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade https://access.redhat.com/errata/RHSA-2026:71179\n\nWorkarounds / mitigations:\n\n- Do not pass untrusted or attacker-influenced git option names to GitPython. Upgrade to GitPython 3.1.58 or later, where option-name (config) injection is fixed.\n\n## Package advisory (CVE-2026-76221)\n\nAffected packages:\n\n- `gitpython < 3.1.58`\n\nPatched in:\n\n- `gitpython 3.1.58`\n\nSource: https://osv.dev/vulnerability/GHSA-jm78-9fvv-mhgr","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}