High severity7.0NVD Advisory· Published Aug 1, 2026· Updated Sep 16, 2026
CVE-2026-67326
CVE-2026-67326
Description
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <3.1.50
Patches
Vulnerability mechanics
References
2- github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2wnvdExploitVendor Advisory
- www.vulncheck.com/advisories/gitpython-before-newline-injection-via-config-writer-sectionnvdThird Party Advisory
News mentions
1- GitPython: Five Vulnerabilities Disclosed Together, Ranging From Command Injection to Env Var LeaksVypr Intelligence · Aug 2, 2026