---
id: CVE-2026-78676
title: >-
  gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection
  (CVE-2026-78676)
summary: >-
  GitPython before 3.1.59 fails to safely re-serialize multi-line git-config
  values during write operations, corrupting dormant quoted values into injected
  directives like core.hooksPath. Attackers can craft config files with embedded
  newlin…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe:
  - CWE-88
  - CWE-94
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openstack_platform 16.2
  - satellite 6
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - satellite 6.18
  - satellite 6.19
patched:
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - satellite 6.18
  - satellite 6.19
published: '2026-08-25'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:59:40+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78676.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78676.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-78676'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2523197'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-78676'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78676'
  - url: >-
      https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w
  - url: >-
      https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection
  - url: 'https://access.redhat.com/errata/RHSA-2026:71210'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68764'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68771'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68780'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68776'
  - url: 'https://github.com/gitpython-developers/GitPython'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3786.yaml
  - url: 'https://github.com/advisories/GHSA-284h-m62q-gf8w'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00775
epssPercentile: 0.53902
aliases:
  - GHSA-284h-m62q-gf8w
  - PYSEC-2026-3786
ecosystem: pip
ingestedAt: '2026-09-03T19:32:11.753Z'
---

## Overview

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

## Vendor advisories

- **RHSA-2026:71210** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71210)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)
- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)
- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)
- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)
- **Red Hat VEX** · Critical · affected: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 16.2, … · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78676.json)

**gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection** — rated Critical by Red Hat. Released 2026-08-25, updated 2026-09-24.

Affected:

- Exploit Intelligence
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenStack Platform 16.2
- Red Hat Satellite 6

Fixed:

- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Satellite 6.18
- Red Hat Satellite 6.19

No fix planned:

- Exploit Intelligence
- Red Hat Ansible Automation Platform 2
- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenStack Platform 16.2
- Red Hat Satellite 6

Not affected:

- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Migration Toolkit for Applications 8
- Red Hat Ansible Automation Platform 2
- Red Hat Hardened Images
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading https://access.redhat.com/errata/RHSA-2026:71210
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade https://access.redhat.com/errata/RHSA-2026:71179
For Red Hat Lightspeed in Satellite installation see the Red Hat Satellite documentation. https://access.redhat.com/errata/RHSA-2026:68764

## Package advisory (CVE-2026-78676)

Affected packages:

- `gitpython < 3.1.59`

Patched in:

- `gitpython 3.1.59`

Source: https://osv.dev/vulnerability/GHSA-284h-m62q-gf8w
