{"id":"CVE-2026-78675","title":"GitPython: GitPython: Local file content disclosure via malicious .gitmodules (CVE-2026-78675)","summary":"A flaw was found in GitPython that could allow for local file content disclosure. This vulnerability occurs because GitPython does not properly disable merge_includes when processing .gitmodules files. An attacker could exploit this by cre…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cvssSource":"vendor","cwe":["CWE-73","CWE-200"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","migration_toolkit_for_applications 8","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openstack_platform 16.2","openstack_platform 17.1","satellite 6"],"patched":["gitpython 3.1.59"],"published":"2026-08-25","updated":"2026-09-10","sourceUpdated":"2026-09-10T07:53:06+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78675.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78675.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-78675"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523214"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78675"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78675"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules"},{"url":"https://github.com/gitpython-developers/GitPython/pull/2211"},{"url":"https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3785.yaml"},{"url":"https://github.com/advisories/GHSA-7833-fr7j-v32q"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa","score-dispute"],"epss":0.00119,"epssPercentile":0.02037,"aliases":["GHSA-7833-fr7j-v32q","PYSEC-2026-3785"],"ecosystem":"pip","scores":{"vendor":5.5,"osv":8.4,"ghsa":8.4},"ingestedAt":"2026-09-03T19:32:11.707Z","slug":"CVE-2026-78675","body":"## Overview\n\nA flaw was found in GitPython that could allow for local file content disclosure. This vulnerability occurs because GitPython does not properly disable merge_includes when processing .gitmodules files. An attacker could exploit this by creating a specially crafted .gitmodules file with include directives that reference sensitive local files. When a user interacts with the repository's submodules, the system may inadvertently reveal the first line of these sensitive files through an error message.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, … · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78675.json)\n\n**GitPython: GitPython: Local file content disclosure via malicious .gitmodules** — rated Moderate by Red Hat. Released 2026-08-25, updated 2026-09-10.\n\nAffected:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat Satellite 6\n\nNo fix planned:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Hardened Images\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q.\n\n## Package advisory (CVE-2026-78675)\n\nAffected packages:\n\n- `gitpython < 3.1.59`\n\nPatched in:\n\n- `gitpython 3.1.59`\n\nSource: https://osv.dev/vulnerability/GHSA-7833-fr7j-v32q","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":201933,"id":"CVE-2026-78675","ts":1789399993066,"field":"cvss","old":"8.4","new":"5.5"},{"seq":201932,"id":"CVE-2026-78675","ts":1789399993066,"field":"severity","old":"high","new":"medium"},{"seq":200663,"id":"CVE-2026-78675","ts":1789397582697,"field":"cvss","old":"5.5","new":"8.4"},{"seq":200662,"id":"CVE-2026-78675","ts":1789397582697,"field":"severity","old":"medium","new":"high"},{"seq":199370,"id":"CVE-2026-78675","ts":1789395475238,"field":"cvss","old":"8.4","new":"5.5"},{"seq":199369,"id":"CVE-2026-78675","ts":1789395475238,"field":"severity","old":"high","new":"medium"},{"seq":198615,"id":"CVE-2026-78675","ts":1789392185058,"field":"cvss","old":"5.5","new":"8.4"},{"seq":198614,"id":"CVE-2026-78675","ts":1789392185058,"field":"severity","old":"medium","new":"high"},{"seq":196946,"id":"CVE-2026-78675","ts":1789384272854,"field":"cvss","old":"8.4","new":"5.5"},{"seq":196945,"id":"CVE-2026-78675","ts":1789384272854,"field":"severity","old":"high","new":"medium"},{"seq":194077,"id":"CVE-2026-78675","ts":1789378690575,"field":"cvss","old":"5.5","new":"8.4"},{"seq":194076,"id":"CVE-2026-78675","ts":1789378690575,"field":"severity","old":"medium","new":"high"},{"seq":192864,"id":"CVE-2026-78675","ts":1789376494166,"field":"cvss","old":"8.4","new":"5.5"},{"seq":192863,"id":"CVE-2026-78675","ts":1789376494166,"field":"severity","old":"high","new":"medium"},{"seq":191651,"id":"CVE-2026-78675","ts":1789373587310,"field":"cvss","old":"5.5","new":"8.4"},{"seq":191650,"id":"CVE-2026-78675","ts":1789373587310,"field":"severity","old":"medium","new":"high"},{"seq":190436,"id":"CVE-2026-78675","ts":1789369449194,"field":"cvss","old":"8.4","new":"5.5"},{"seq":190435,"id":"CVE-2026-78675","ts":1789369449194,"field":"severity","old":"high","new":"medium"},{"seq":189223,"id":"CVE-2026-78675","ts":1789368370765,"field":"cvss","old":"5.5","new":"8.4"},{"seq":189222,"id":"CVE-2026-78675","ts":1789368370765,"field":"severity","old":"medium","new":"high"},{"seq":188006,"id":"CVE-2026-78675","ts":1789365211229,"field":"cvss","old":"8.4","new":"5.5"},{"seq":188005,"id":"CVE-2026-78675","ts":1789365211229,"field":"severity","old":"high","new":"medium"},{"seq":186793,"id":"CVE-2026-78675","ts":1789363452539,"field":"cvss","old":"5.5","new":"8.4"},{"seq":186792,"id":"CVE-2026-78675","ts":1789363452539,"field":"severity","old":"medium","new":"high"},{"seq":185579,"id":"CVE-2026-78675","ts":1789361194956,"field":"cvss","old":"8.4","new":"5.5"},{"seq":185578,"id":"CVE-2026-78675","ts":1789361194956,"field":"severity","old":"high","new":"medium"},{"seq":184366,"id":"CVE-2026-78675","ts":1789358316481,"field":"cvss","old":"5.5","new":"8.4"},{"seq":184365,"id":"CVE-2026-78675","ts":1789358316481,"field":"severity","old":"medium","new":"high"},{"seq":182617,"id":"CVE-2026-78675","ts":1789354302311,"field":"cvss","old":"8.4","new":"5.5"},{"seq":182616,"id":"CVE-2026-78675","ts":1789354302311,"field":"severity","old":"high","new":"medium"},{"seq":181410,"id":"CVE-2026-78675","ts":1789353277348,"field":"cvss","old":"5.5","new":"8.4"},{"seq":181409,"id":"CVE-2026-78675","ts":1789353277348,"field":"severity","old":"medium","new":"high"},{"seq":180203,"id":"CVE-2026-78675","ts":1789350265102,"field":"cvss","old":"8.4","new":"5.5"},{"seq":180202,"id":"CVE-2026-78675","ts":1789350265102,"field":"severity","old":"high","new":"medium"},{"seq":178996,"id":"CVE-2026-78675","ts":1789348252489,"field":"cvss","old":"5.5","new":"8.4"},{"seq":178995,"id":"CVE-2026-78675","ts":1789348252489,"field":"severity","old":"medium","new":"high"},{"seq":177789,"id":"CVE-2026-78675","ts":1789346355628,"field":"cvss","old":"8.4","new":"5.5"},{"seq":177788,"id":"CVE-2026-78675","ts":1789346355628,"field":"severity","old":"high","new":"medium"},{"seq":176582,"id":"CVE-2026-78675","ts":1789343156371,"field":"cvss","old":"5.5","new":"8.4"},{"seq":176581,"id":"CVE-2026-78675","ts":1789343156371,"field":"severity","old":"medium","new":"high"},{"seq":174699,"id":"CVE-2026-78675","ts":1789334852780,"field":"cvss","old":"8.4","new":"5.5"},{"seq":174698,"id":"CVE-2026-78675","ts":1789334852780,"field":"severity","old":"high","new":"medium"},{"seq":173494,"id":"CVE-2026-78675","ts":1789333640962,"field":"cvss","old":"5.5","new":"8.4"},{"seq":173493,"id":"CVE-2026-78675","ts":1789333640962,"field":"severity","old":"medium","new":"high"},{"seq":172308,"id":"CVE-2026-78675","ts":1789331080249,"field":"cvss","old":"8.4","new":"5.5"},{"seq":172307,"id":"CVE-2026-78675","ts":1789331080249,"field":"severity","old":"high","new":"medium"},{"seq":171122,"id":"CVE-2026-78675","ts":1789328748197,"field":"cvss","old":"5.5","new":"8.4"},{"seq":171121,"id":"CVE-2026-78675","ts":1789328748197,"field":"severity","old":"medium","new":"high"},{"seq":169917,"id":"CVE-2026-78675","ts":1789327144231,"field":"cvss","old":"8.4","new":"5.5"},{"seq":169916,"id":"CVE-2026-78675","ts":1789327144231,"field":"severity","old":"high","new":"medium"}]}