---
id: CVE-2026-42284
title: >-
  GitPython: GitPython: Arbitrary code execution via improper validation of
  clone options (CVE-2026-42284)
summary: >-
  A flaw was found in GitPython, a Python library for interacting with Git
  repositories. A remote attacker could exploit an input validation
  vulnerability in the `_clone()` function. By crafting a malicious string in
  the `multi_options` para…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-88
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - satellite 6
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_19_for_rhel 9
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 2.25
  - openshift_ai 3.4
  - satellite 6.18
  - satellite 6.19
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_19_for_rhel 9
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 2.25
  - openshift_ai 3.4
  - satellite 6.18
  - satellite 6.19
published: '2026-05-07'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:59:06+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42284.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42284.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42284'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467800'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42284'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42284'
  - url: 'https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47'
  - url: >-
      https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-x2qx-6953-8485
  - url: 'https://access.redhat.com/errata/RHSA-2026:42078'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42079'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63385'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71210'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42132'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67279'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68764'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68771'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68780'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68776'
  - url: 'https://github.com/gitpython-developers/GitPython'
  - url: 'https://www.tenable.com/cve/CVE-2026-32686'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00707
epssPercentile: 0.51432
aliases:
  - GHSA-x2qx-6953-8485
  - PYSEC-2026-2161
ecosystem: pip
ingestedAt: '2026-07-13T18:58:04.843Z'
---

## Overview

A flaw was found in GitPython, a Python library for interacting with Git repositories. A remote attacker could exploit an input validation vulnerability in the `_clone()` function. By crafting a malicious string in the `multi_options` parameter, an attacker could bypass validation. This allows for the injection of arbitrary Git configurations, such as `core.hooksPath`, leading to the execution of attacker-controlled hooks and ultimately, arbitrary code execution during a clone operation.

## Vendor advisories

- **RHSA-2026:42078** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42078)
- **RHSA-2026:42079** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42079)
- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)
- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:42132** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42132)
- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)
- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)
- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Satellite 6 · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42284.json)
- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)
- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)

**GitPython: GitPython: Arbitrary code execution via improper validation of clone options** — rated Important by Red Hat. Released 2026-05-07, updated 2026-09-24.

Affected:

- Exploit Intelligence
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Satellite 6

Fixed:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Exploit Intelligence
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Satellite 6

Not affected:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4

## Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:42078
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:42079
Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-42284)

Affected packages:

- `gitpython < 3.1.47`

Patched in:

- `gitpython 3.1.47`

Source: https://osv.dev/vulnerability/GHSA-x2qx-6953-8485
