{"id":"CVE-2026-78679","title":"GitPython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)","summary":"A flaw was found in GitPython. A remote attacker with low privileges can exploit a vulnerability in the `TagReference.create()` function, where a positional reference parameter bypasses a security guard. This allows the attacker to supply …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cvssSource":"vendor","cwe":["CWE-22","CWE-88","CWE-200"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","migration_toolkit_for_applications 8","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openstack_platform 16.2","satellite 6","ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite 6.18","satellite 6.19"],"patched":["ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite 6.18","satellite 6.19"],"published":"2026-08-25","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:28:26+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78679.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78679.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-78679"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523205"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78679"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78679"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create"},{"url":"https://access.redhat.com/errata/RHSA-2026:59135"},{"url":"https://access.redhat.com/errata/RHSA-2026:59136"},{"url":"https://access.redhat.com/errata/RHSA-2026:68764"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"},{"url":"https://github.com/gitpython-developers/GitPython/pull/2208"},{"url":"https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59"},{"url":"https://github.com/advisories/GHSA-3wxw-xv34-2frg"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00241,"epssPercentile":0.15565,"aliases":["GHSA-3wxw-xv34-2frg"],"ecosystem":"pip","ingestedAt":"2026-09-08T20:10:03.214Z","slug":"CVE-2026-78679","body":"## Overview\n\nA flaw was found in GitPython. A remote attacker with low privileges can exploit a vulnerability in the `TagReference.create()` function, where a positional reference parameter bypasses a security guard. This allows the attacker to supply a specially crafted reference value, such as `--file=<path>`, to read arbitrary files on the system. The contents of these files are then returned within the annotated tag message, leading to information disclosure.\n\n## Vendor advisories\n\n- **RHSA-2026:59135** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59135)\n- **RHSA-2026:59136** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59136)\n- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)\n- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Migration Toolkit for Applications 8, Red Hat AI Inference Server, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78679.json)\n\n**GitPython: GitPython: Arbitrary file read via TagReference.create()** — rated Moderate by Red Hat. Released 2026-08-25, updated 2026-09-21.\n\nAffected:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Satellite 6.18\n- Red Hat Satellite 6.19\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Ansible Automation Platform 2\n- Red Hat Hardened Images\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n\n## Remediation\n\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59135\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:59136\nFor Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68764\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. For additional information, refer to the upstream advisory at https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg.\n\n## Package advisory (CVE-2026-78679)\n\nAffected packages:\n\n- `gitpython < 3.1.59`\n\nPatched in:\n\n- `gitpython 3.1.59`\n\nSource: https://osv.dev/vulnerability/GHSA-3wxw-xv34-2frg","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}