CVE-2026-67323
Red Hat Security Advisory: satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview
Beschreibung
GitPython vor Version 3.1.51 schützt sich nicht ausreichend gegen gefährliche Git-Optionen, die als Schlüsselwortargumente in `Repo.archive()` und `git.ls_remote()` übergeben werden, was zu einer Befehlseinschleusung durch Optionen wie `--exec`/`--upload-pack` (was zur willkürlichen Ausführung von Befehlen führen kann) führt. Darüber hinaus prüfen `Repo.iter_commits()` und `Repo.blame()` keine Revision-Argumente mit einem vorangestellten Bindestrich, sodass eine Revision wie `--output=<path>` Git dazu veranlassen kann, eine beliebige Datei zu öffnen und zu kürzen. Die Ausnutzung erfordert eine Anwendung, die vom Angreifer kontrollierte Argumente an diese Methoden weitergibt.
Metriken
Weakness-Klassen (CWE)
CWE-77Class
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
cwe.mitre.org →
Betroffene Betriebssysteme
linux
redhat / enterprise_linux_ai3.0
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
encode
starlette0.8.3 – 1.0.1
gitpython_project
gitpython3.1.51
gitpython_project
gitpython3.1.52
pypi
aiohttp0.1
pypi
aiohttp0.10.0
pypi
aiohttp0.10.1
pypi
aiohttp0.10.2
pypi
aiohttp0.11.0
pypi
aiohttp0.12.0
pypi
aiohttp0.13.0
pypi
aiohttp0.13.1
pypi
aiohttp0.14.0
pypi
aiohttp0.14.1
pypi
aiohttp0.14.2
pypi
aiohttp0.14.3
pypi
aiohttp0.14.4
pypi
aiohttp0.15.0
pypi
aiohttp0.15.1
pypi
aiohttp0.15.2
pypi
aiohttp0.15.3
pypi
aiohttp0.16.0
pypi
aiohttp0.16.1
pypi
aiohttp0.16.2
pypi
aiohttp0.16.3
Quellen & Referenzen
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22vweb
- https://github.com/aio-libs/aiohttp/pull/13017web
- https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98web
- https://github.com/aio-libs/aiohttppackage
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2web
- https://pypi.org/project/aiohttppackage
- https://github.com/advisories/GHSA-mfx4-hv73-q22vadvisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-69243advisory
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-956x-8gvw-wg5vweb
- https://github.com/gitpython-developers/GitPython/pull/2163web
- https://github.com/gitpython-developers/GitPython/commit/701ce32fe5ba8cb622c0e0342a376a6beb47d738web
- https://github.com/gitpython-developers/GitPythonpackage
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.51web
- https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-unguarded-git-optionsthird-party-advisory
- https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mrweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-48710advisory
- https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6web
- https://www.x41-dsec.de/lab/advisories/x41-2026-002-starletteweb
- https://www.secwest.net/starletteweb
- https://www.cve.org/CVERecord?id=CVE-2026-48710web
Verknüpfte CVEs
- CVE-2026-69244
AIOHTTP ist ein asynchroner HTTP-Client/Server-Framework für asyncio und Python.
high - CVE-2026-69243
AIOHTTP ist ein asynchroner HTTP-Client/Server-Framework für asyncio und Python.
medium - CVE-2026-67325
GitPython vor Version 3.1.51 enthält eine unvollständige Blacklist für die Befehlseinschleusung, die das Abkürzungsfeature von gits Lango…
highCVSSv3 8.8 - CVE-2026-67322
GitPython vor Version 3.1.52 ist anfällig für die Exfiltration von Umgebungsvariablen in `Repo.clone_from()`.
highCVSSv3 7.5 - CVE-2026-48710Aktiv ausgenutzt
Starlette ist ein leichtgewichtiges ASGI-Framework/Toolkit.
criticalCVSSv3 6.5