{"id":"CVE-2026-78676","title":"gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)","summary":"GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlin…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":["CWE-88","CWE-94"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","migration_toolkit_for_applications 8","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openstack_platform 16.2","satellite 6","satellite 6.18","satellite 6.19"],"patched":["satellite 6.18","satellite 6.19"],"published":"2026-08-25","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:27:51+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78676.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78676.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-78676"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523197"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78676"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78676"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection"},{"url":"https://access.redhat.com/errata/RHSA-2026:68764"},{"url":"https://access.redhat.com/errata/RHSA-2026:68771"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"},{"url":"https://access.redhat.com/errata/RHSA-2026:68776"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml"},{"url":"https://github.com/advisories/GHSA-284h-m62q-gf8w"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00426,"epssPercentile":0.36386,"aliases":["GHSA-284h-m62q-gf8w","PYSEC-2026-3786"],"ecosystem":"pip","ingestedAt":"2026-09-03T19:32:11.753Z","slug":"CVE-2026-78676","body":"## Overview\n\nGitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.\n\n## Vendor advisories\n\n- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)\n- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)\n- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)\n- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)\n- **Red Hat VEX** · Critical · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Migration Toolkit for Applications 8, Red Hat AI Inference Server, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78676.json)\n\n**gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection** — rated Critical by Red Hat. Released 2026-08-25, updated 2026-09-21.\n\nAffected:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Satellite 6.18\n- Red Hat Satellite 6.19\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Hardened Images\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n\n## Remediation\n\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68764\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68771\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68780\n\n## Package advisory (CVE-2026-78676)\n\nAffected packages:\n\n- `gitpython < 3.1.59`\n\nPatched in:\n\n- `gitpython 3.1.59`\n\nSource: https://osv.dev/vulnerability/GHSA-284h-m62q-gf8w","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":5476,"id":"CVE-2026-78676","ts":1788887288537,"field":"cvss","old":null,"new":"9.8"},{"seq":5475,"id":"CVE-2026-78676","ts":1788887288537,"field":"severity","old":"none","new":"critical"},{"seq":4359,"id":"CVE-2026-78676","ts":1788886401261,"field":"cvss","old":"9.8","new":null},{"seq":4358,"id":"CVE-2026-78676","ts":1788886401261,"field":"severity","old":"critical","new":"none"},{"seq":3179,"id":"CVE-2026-78676","ts":1788883133261,"field":"cvss","old":null,"new":"9.8"},{"seq":3178,"id":"CVE-2026-78676","ts":1788883133261,"field":"severity","old":"none","new":"critical"}]}