Remote Code Execution Vulnerability in GitPython by GitPython Developers
CVE-2026-76218

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76218?

A vulnerability in GitPython prior to version 3.1.58 allows attackers to execute arbitrary code through the Repo.init method by forwarding unchecked git options. Exploiting this vulnerability, an attacker can point to a directory containing malicious git hooks. When git operations are initiated on the repository, these hooks are executed, leading to potential remote code execution and compromising the security of the affected system.

Affected Version(s)

GitPython 0 < 3.1.58

GitPython 3.1.58

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
BarakSrour
.