CVE-2026-45570Medium· 6.3▾ SunlitA flaw was found in go-git, a library used for Git operations. The component responsible for secure shell (SSH) communication does not correctly handle special characters in repository paths. This oversight allows a remote attacker to mani…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
6.3 → —
medium → low
— → 6.3
low → medium
6.3 → —
medium → low
— → 6.3
low → medium
6.3 → —
medium → low
— → 6.3
low → medium
Last analysed / modified upstream
A flaw was found in go-git, a library used for Git operations. The component responsible for secure shell (SSH) communication does not correctly handle special characters in repository paths. This oversight allows a remote attacker to manipulate the command executed on the server by including a specially crafted repository path. This could result in the appending of additional shell commands, potentially leading to unintended actions on the system.
github.com/go-git/go-git: go-git: Shell command injection in SSH transport — rated Moderate by Red Hat. Released 2026-05-27, updated 2026-09-21.
Fixed:
Not affected:
Before you apply this update, make sure all previously released errata that are relevant to your system are applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67543
Affected packages:
github.com/go-git/go-git/v5 < 5.19.1github.com/go-git/go-git/v6 < 6.0.0-alpha.4github.com/go-git/go-git <= 4.7.0Patched in:
github.com/go-git/go-git/v5 5.19.1github.com/go-git/go-git/v6 6.0.0-alpha.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78679Medium· 6.5GitPython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)
CVE-2026-78678Medium· 6.5gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)
CVE-2026-78676Critical· 9.8gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)
CVE-2026-79675High· 8.1nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options (CVE-2026-79675)
CVE-2026-76220High· 8.8gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220)
CVE-2026-76218High· 7.5gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218)