---
id: CVE-2026-76222
title: >-
  gitpython: GitPython: Arbitrary file creation via path traversal in
  .gitmodules submodule names (CVE-2026-76222)
summary: >-
  A flaw was found in GitPython where it fails to properly validate submodule
  names within .gitmodules files. A remote attacker could craft a malicious Git
  repository containing specially formed submodule names with directory
  traversal seque…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L'
cvssSource: vendor
cwe:
  - CWE-22
  - CWE-73
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - migration_toolkit_for_applications 8
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openstack_platform 16.2
  - satellite 6
  - satellite_6_19_for_rhel 9
  - satellite 6.18
  - satellite 6.19
patched:
  - satellite_6_19_for_rhel 9
  - satellite 6.18
  - satellite 6.19
published: '2026-08-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T10:27:49+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76222.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76222.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-76222'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2519609'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-76222'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76222'
  - url: >-
      https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc
  - url: >-
      https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-gitmodules-submodule-name
  - url: 'https://access.redhat.com/errata/RHSA-2026:63385'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68764'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68771'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68780'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68776'
  - url: 'https://github.com/gitpython-developers/GitPython/pull/2202'
  - url: >-
      https://github.com/gitpython-developers/GitPython/commit/4299c990e1ca21896f9485277caf7bb0ae5b404c
  - url: >-
      https://github.com/gitpython-developers/GitPython/commit/e4b8e7d026ca6abb4cf604f8e77093432ce23c06
  - url: 'https://github.com/gitpython-developers/GitPython'
  - url: 'https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3784.yaml
  - url: 'https://github.com/advisories/GHSA-hmq2-w58f-27jc'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00333
epssPercentile: 0.26721
aliases:
  - GHSA-hmq2-w58f-27jc
  - PYSEC-2026-3784
ecosystem: pip
ingestedAt: '2026-08-20T19:23:06.238Z'
---

## Overview

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal sequences. When GitPython processes these malicious submodule names during repository initialization, it could lead to the creation of attacker-controlled Git repositories at arbitrary locations on the filesystem, potentially impacting system integrity.

## Vendor advisories

- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)
- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)
- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)
- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)
- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Migration Toolkit for Applications 8, Red Hat AI Inference Server, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-76222.json)

**gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names** — rated Important by Red Hat. Released 2026-08-19, updated 2026-09-21.

Affected:

- Exploit Intelligence
- Migration Toolkit for Applications 8
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenStack Platform 16.2
- Red Hat Satellite 6

Fixed:

- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- Exploit Intelligence
- Red Hat Ansible Automation Platform 2
- Migration Toolkit for Applications 8
- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenStack Platform 16.2
- Red Hat Satellite 6

Not affected:

- Red Hat Satellite 6.19 for RHEL 9
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat Ansible Automation Platform 2
- Red Hat Hardened Images
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:63385
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68764
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68771

Workarounds / mitigations:

- There is no mitigation beyond not cloning or initializing git submodules from untrusted repositories. Upgrade to GitPython 3.1.58 or later when it becomes available.

## Package advisory (CVE-2026-76222)

Affected packages:

- `gitpython < 3.1.58`

Patched in:

- `gitpython 3.1.58`

Source: https://osv.dev/vulnerability/GHSA-hmq2-w58f-27jc
