CVE-2026-76220High· 8.8▾ TwilightA flaw was found in GitPython. A remote attacker can bypass the `check_unsafe_options` guard by combining a single-character keyword argument with `split_single_char_options=False`. This allows the attacker to supply a crafted dictionary o…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
0.5% → 0.6%
Last analysed / modified upstream
A flaw was found in GitPython. A remote attacker can bypass the check_unsafe_options guard by combining a single-character keyword argument with split_single_char_options=False. This allows the attacker to supply a crafted dictionary of keyword arguments to guarded methods, such as clone_from, leading to arbitrary operating system command execution.
gitpython: GitPython: Arbitrary command execution via crafted kwargs — rated Important by Red Hat. Released 2026-08-19, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For detailed instructions how to apply this update, refer to:
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385 For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68764 For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68771
Workarounds / mitigations:
Affected packages:
gitpython < 3.1.58Patched in:
gitpython 3.1.58Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76221High· 8.8gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221)
CVE-2026-76218High· 7.5gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218)
CVE-2026-76219High· 8.1gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219)
CVE-2025-69227High· 7.5aiohttp: aiohttp: Denial of Service via specially crafted POST request (CVE-2025-69227)
CVE-2026-85013High· 7.3A flaw was found in environment-modules
CVE-2026-10805Medium· 6.7A flaw was found in NetworkManager