CVE-2026-78675Medium· 5.5▾ SunlitA flaw was found in GitPython that could allow for local file content disclosure. This vulnerability occurs because GitPython does not properly disable merge_includes when processing .gitmodules files. An attacker could exploit this by cre…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.1%
Last analysed / modified upstream
5.5 → 8.4
medium → high
8.4 → 5.5
high → medium
5.5 → 8.4
medium → high
8.4 → 5.5
high → medium
5.5 → 8.4
medium → high
8.4 → 5.5
high → medium
A flaw was found in GitPython that could allow for local file content disclosure. This vulnerability occurs because GitPython does not properly disable merge_includes when processing .gitmodules files. An attacker could exploit this by creating a specially crafted .gitmodules file with include directives that reference sensitive local files. When a user interacts with the repository's submodules, the system may inadvertently reveal the first line of these sensitive files through an error message.
GitPython: GitPython: Local file content disclosure via malicious .gitmodules — rated Moderate by Red Hat. Released 2026-08-25, updated 2026-09-10.
Affected:
No fix planned:
Not affected:
Fix deferred
Workarounds / mitigations:
Affected packages:
gitpython < 3.1.59Patched in:
gitpython 3.1.59Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78679Medium· 6.5GitPython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)
CVE-2026-78678Medium· 6.5gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)
CVE-2026-76222High· 8.2gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)
CVE-2026-67322High· 7.5GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()
CVE-2026-78676Critical· 9.8gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)
CVE-2026-79674High· 7.5nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)