High severity7.0OSV Advisory· Published Aug 3, 2026· Updated Sep 16, 2026
CVE-2026-69097
CVE-2026-69097
Description
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
33.1.52, 3.1.51, 3.1.50, …+ 1 more
- (no CPE)range: 3.1.52, 3.1.51, 3.1.50, …
- (no CPE)range: <3.1.53
Patches
Vulnerability mechanics
References
2- github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2nvdExploitMitigationVendor Advisory
- www.vulncheck.com/advisories/gitpython-before-config-injection-via-submodule-namesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.