---
id: CVE-2026-44244
title: >-
  GitPython: GitPython: Arbitrary code execution via injected newlines in Git
  configuration (CVE-2026-44244)
summary: >-
  A flaw was found in GitPython, a Python library used to interact with Git
  repositories. The `GitConfigParser.set_value()` function does not properly
  validate input for newlines. This vulnerability allows an attacker to inject
  malicious con…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-1286
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - pen_drive_powered_by_red_hat_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - satellite 6
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_19_for_rhel 9
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 2.25
  - openshift_ai 3.4
  - satellite 6.18
  - satellite 6.19
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_19_for_rhel 9
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 2.25
  - openshift_ai 3.4
  - satellite 6.18
  - satellite 6.19
published: '2026-05-07'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:59:09+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44244.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44244.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-44244'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2467804'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-44244'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44244'
  - url: 'https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49'
  - url: >-
      https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-v87r-6q3f-2j67
  - url: 'https://access.redhat.com/errata/RHSA-2026:42078'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42079'
  - url: 'https://access.redhat.com/errata/RHSA-2026:63385'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71210'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42132'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59153'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67279'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68764'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68771'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68780'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68776'
  - url: 'https://github.com/gitpython-developers/GitPython'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00218
epssPercentile: 0.11005
aliases:
  - GHSA-v87r-6q3f-2j67
  - PYSEC-2026-2163
ecosystem: pip
ingestedAt: '2026-07-13T18:58:03.391Z'
---

## Overview

A flaw was found in GitPython, a Python library used to interact with Git repositories. The `GitConfigParser.set_value()` function does not properly validate input for newlines. This vulnerability allows an attacker to inject malicious configuration settings, specifically the `core.hooksPath`, into a Git repository. Consequently, any Git operation that triggers hooks, such as committing or merging, could lead to arbitrary code execution from an attacker-controlled path.

## Vendor advisories

- **RHSA-2026:42078** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42078)
- **RHSA-2026:42079** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42079)
- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)
- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:42132** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42132)
- **RHSA-2026:59153** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59153)
- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)
- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Pen Drive Powered by Red Hat Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Satellite 6 · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, Pen Drive Powered by Red Hat Lightspeed, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44244.json)
- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)
- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)

**GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration** — rated Important by Red Hat. Released 2026-05-07, updated 2026-09-24.

Affected:

- Exploit Intelligence
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Satellite 6

Fixed:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Exploit Intelligence
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Satellite 6

Not affected:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4

## Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:42078
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:42079
Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385

Workarounds / mitigations:

- To mitigate this issue, applications that use GitPython and process untrusted input for Git configuration values must implement robust input validation and sanitization. This prevents the injection of newlines that could manipulate `core.hooksPath` and lead to arbitrary code execution. Additionally, ensure that applications interacting with Git repositories operate with the principle of least privilege to limit the potential impact of any successful exploitation.

## Package advisory (CVE-2026-44244)

Affected packages:

- `gitpython < 3.1.49`

Patched in:

- `gitpython 3.1.49`

Source: https://osv.dev/vulnerability/GHSA-v87r-6q3f-2j67
