{"id":"CVE-2026-76222","title":"gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)","summary":"A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L","cvssSource":"vendor","cwe":["CWE-22","CWE-73"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","migration_toolkit_for_applications 8","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openstack_platform 16.2","satellite 6","satellite_6_19_for_rhel 9","satellite 6.18","satellite 6.19"],"patched":["satellite_6_19_for_rhel 9","satellite 6.18","satellite 6.19"],"published":"2026-08-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:27:49+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76222.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76222.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-76222"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2519609"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76222"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76222"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:68764"},{"url":"https://access.redhat.com/errata/RHSA-2026:68771"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"},{"url":"https://access.redhat.com/errata/RHSA-2026:68776"},{"url":"https://github.com/gitpython-developers/GitPython/pull/2202"},{"url":"https://github.com/gitpython-developers/GitPython/commit/4299c990e1ca21896f9485277caf7bb0ae5b404c"},{"url":"https://github.com/gitpython-developers/GitPython/commit/e4b8e7d026ca6abb4cf604f8e77093432ce23c06"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml"},{"url":"https://github.com/advisories/GHSA-hmq2-w58f-27jc"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00333,"epssPercentile":0.26721,"aliases":["GHSA-hmq2-w58f-27jc","PYSEC-2026-3784"],"ecosystem":"pip","ingestedAt":"2026-08-20T19:23:06.238Z","slug":"CVE-2026-76222","body":"## Overview\n\nA flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal sequences. When GitPython processes these malicious submodule names during repository initialization, it could lead to the creation of attacker-controlled Git repositories at arbitrary locations on the filesystem, potentially impacting system integrity.\n\n## Vendor advisories\n\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)\n- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)\n- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)\n- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Migration Toolkit for Applications 8, Red Hat AI Inference Server, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76222.json)\n\n**gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names** — rated Important by Red Hat. Released 2026-08-19, updated 2026-09-21.\n\nAffected:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Satellite 6.18\n- Red Hat Satellite 6.19\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Satellite 6.19 for RHEL 9\n- Pen Drive Powered by Red Hat Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat Hardened Images\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor detailed instructions how to apply this update, refer to:\n\nhttps://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68764\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68771\n\nWorkarounds / mitigations:\n\n- There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available.\n\n## Package advisory (CVE-2026-76222)\n\nAffected packages:\n\n- `gitpython < 3.1.58`\n\nPatched in:\n\n- `gitpython 3.1.58`\n\nSource: https://osv.dev/vulnerability/GHSA-hmq2-w58f-27jc","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}