CVE-2026-87817
gitpython: Improper Control of Generation of Code ('Code Injection') (CVE-2026-87817)
Description
A flaw was found in GitPython. This vulnerability allows a remote attacker to execute arbitrary code. By failing to properly validate the git directory location, GitPython allows attackers to impersonate the git directory using tracked files such as gitdir, commondir, and HEAD. An attacker can then place a malicious pre-commit hook in the tracked hooks directory, which executes when a victim calls index.commit() on a cloned or opened repository.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
0.1.70.2.0-beta10.3.0-beta10.3.0-beta20.3.1-beta20.3.20.3.2.10.3.2.RC10.3.30.3.40.3.50.3.60.3.71.0.01.0.11.0.22.0.02.0.12.0.22.0.32.0.42.0.52.0.62.0.72.0.82.0.92.0.9.dev02.0.9.dev12.1.02.1.12.1.102.1.112.1.122.1.132.1.142.1.152.1.22.1.32.1.42.1.52.1.62.1.72.1.82.1.93.0.03.0.13.0.23.0.3Metrics
Show all metrics
Weakness classes (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
References & sources
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-239g-whfq-7xj9vendor-advisory
- https://www.vulncheck.com/advisories/gitpython-before-3.1.60-remote-code-execution-via-git-directory-impersonationthird-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-87817advisory
- https://github.com/gitpython-developers/GitPython/pull/2218web
- https://github.com/gitpython-developers/GitPython/commit/c7cf4d13b1ed0a2e70f2a1f3c6b4fc6c2652cf0bweb
- https://github.com/gitpython-developers/GitPythonpackage
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.60web
- https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3982.yamlweb
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-16 15:24 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* versions up to (excluding) 3.1.60
- Reference Type: VulnCheck: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-239g-whfq-7xj9 Types: Exploit, Mitigation, Vendor Advisory
- Reference Type: VulnCheck: https://www.vulncheck.com/advisories/gitpython-before-3.1.60-remote-code-execution-via-git-directory-impersonation Types: Third Party Advisory
- CVE Modified2026-09-10 15:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-87817","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-09-09 12:17 UTC· disclosure@vulncheck.com
- Description: GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE: CWE-94