Vulnerability Description
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitpython Project | Gitpython | < 3.1.59 |
Related Weaknesses (CWE)
References
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-ExploitVendor AdvisoryMitigation
- https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-Third Party Advisory
FAQ
What is CVE-2026-78676?
CVE-2026-78676 is a vulnerability with a CVSS score of 9.8 (CRITICAL). GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can ...
How severe is CVE-2026-78676?
CVE-2026-78676 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-78676?
Check the references section above for vendor advisories and patch information. Affected products include: Gitpython Project Gitpython.