VYPR
Vypr IntelligenceAI-generatedAug 19, 2026· 6 CVEs

Gitpython: Six High-Severity Vulnerabilities Patched in Version 3.1.58

Six vulnerabilities, including RCE and arbitrary file overwrite, were disclosed for Gitpython versions prior to 3.1.58, all patched in a single update.

Key findings

  • Six vulnerabilities in Gitpython (versions before 3.1.58) disclosed together on 2026-08-19.
  • High severity flaws include RCE, arbitrary file overwrite, and path traversal.
  • Vulnerabilities stem from improper handling of submodule names, git options, and file operations.
  • All issues patched in Gitpython version 3.1.58.
  • Users urged to update immediately to mitigate risks.

On August 19, 2026, a batch of six vulnerabilities was disclosed for the Gitpython library, affecting versions prior to 3.1.58. These vulnerabilities, all detailed in a single advisory, range in severity from Medium to High, with CVSS scores up to 8.8. The disclosures highlight significant security weaknesses in how Gitpython handles submodule names, configuration directives, command options, and file operations, potentially exposing users to arbitrary code execution, arbitrary file writes, and repository path manipulation.

Several of the disclosed vulnerabilities center on the improper handling of Git options and configurations. CVE-2026-76221, a High severity vulnerability (CVSSv3 8.8), arises from a config-name injection flaw in the option-name validator. This allows attackers to forge arbitrary git-config directives by injecting special characters into option names, potentially leading to malicious configurations. Similarly, CVE-2026-76220 (High, CVSSv3 8.8) details a command execution vulnerability in the check_unsafe_options guard, which can be bypassed by specific argument combinations, enabling the execution of unintended commands during Git operations like clone_from. CVE-2026-76218 (High, CVSSv3 7.5) also involves unsafe git options, specifically within the Repo.init functionality, where a template parameter can be manipulated to point to a directory containing malicious git hooks, leading to remote code execution when the repository is initialized.

Another group of vulnerabilities pertains to file manipulation and path traversal. CVE-2026-76222 (High, CVSSv3 8.2) addresses a failure to validate submodule names from .gitmodules files. Attackers can craft malicious repositories with submodule names containing traversal sequences, allowing Gitpython to create Git repositories at arbitrary filesystem paths outside the intended clone directory. CVE-2026-76219 (High, CVSSv3 8.1) describes an arbitrary file overwrite vulnerability in several IndexFile methods (from_tree, reset, merge_tree). By influencing treeish strings and injecting options like --index-output, attackers can overwrite arbitrary files. Lastly, CVE-2026-76217 (Medium, CVSSv3 6.5) involves improper validation of options passed to git rm and git checkout commands within IndexFile.remove() and Head.checkout(). This allows attackers to use parameters like --pathspec-from-file to read arbitrary files accessible to the process.

All six vulnerabilities were patched in Gitpython version 3.1.58. Users are strongly advised to update to this version or later to mitigate the risks associated with these security flaws. The consistent patching across multiple bug classes in this single release indicates a comprehensive security update addressing the identified weaknesses.

This coordinated disclosure of six vulnerabilities underscores the importance of regularly updating development dependencies like Gitpython. The breadth of issues, including remote code execution and arbitrary file overwrite capabilities, presents a significant risk to projects relying on this library. Developers should prioritize updating to version 3.1.58 to ensure their projects are protected against these newly disclosed threats. The consistent patching across multiple bug classes in this single release indicates a comprehensive security update addressing the identified weaknesses.

The vulnerabilities disclosed include:

  • CVE-2026-76222: Arbitrary filesystem path creation via submodule name traversal.
  • CVE-2026-76221: Config-name injection for forging git-config directives.
  • CVE-2026-76220: Command execution bypass via unsafe option handling.
  • CVE-2026-76219: Arbitrary file overwrite in IndexFile methods.
  • CVE-2026-76218: Remote code execution via Repo.init template parameter.
  • CVE-2026-76217: Arbitrary file read via git rm and git checkout options.

All affected versions are prior to 3.1.58. The fix is available in Gitpython 3.1.58.

The coordinated disclosure of six vulnerabilities for the Gitpython library highlights critical security flaws affecting versions prior to 3.1.58. These issues, ranging from arbitrary file overwrite to remote code execution, were all patched in version 3.1.58.

The vulnerabilities include:

Users are urged to update to Gitpython 3.1.58 or later.

AI-written article. Grounded in 6 CVE records listed below.
Gitpython: Six High-Severity Vulnerabilities Patched in Version 3.1.58 · VYPR