CVE-2026-100689
published 2026-09-26CVE-2026-100689: GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix…
PriorityP434medium5.9CVSS 3.1
AVNACHPRNUIRSUCNIHAL
EPSS
0.40%
32.2th percentile
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPython's own containment guard Submodule._to_relative_path() is applied in add() and move(), Submodule.update() derives the absolute checkout location from the raw `path` value without that guard. A .gitmodules entry containing directory traversal components (e.g., path = ../../../tmp/escaped) can therefore cause directories to be created via os.makedirs() outside the repository working tree, populated from the submodule URL on the clone path, and removed via shutil.rmtree() when force_remove is used. Exploitation requires an application flow that updates submodules at a non-HEAD commit (such as a historical-commit API); the common clone-then-update flow re-derives the path from a canonical tree lookup and is not affected. The issue is fixed in GitPython 3.1.62.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-25 | hub-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| exploit-intelligence | vulnerability-analysis-rhel9 | — | — |
| gitpython-developers | gitpython | < 3.1.62 | 3.1.62 |
| gitpython_project | gitpython | — | — |
| mta | mta-solution-server-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhelai3 | disk-image-cuda-rhel9 | — | — |
| rhoai | odh-feature-server-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
GitPython: GitPython: Directory traversal via untrusted submodule path
vendor_redhat·2026-09-26·CVSS 5.9
CVE-2026-100689 [MEDIUM] CWE-22 GitPython: GitPython: Directory traversal via untrusted submodule path
GitPython: GitPython: Directory traversal via untrusted submodule path
A flaw was found in GitPython. When updating submodules, GitPython fails to properly validate the submodule path specified in a repository's configuration file. A remote attacker could exploit this vulnerability by supplying a crafted repository containing directory traversal sequences in the submodule configuration. Successful exploitation allows files and directories to be created, populated, or deleted outside the intended repository working tree.
Package: exploit-intelligence/vulnerability-analysis-rhel9 (Exploit Intelligence) - Out of support scope
Package: mta/mta-solution-server-rhel9 (Migration Toolkit for Applications 8) - Out of support scope
Package: rhaiis/vllm-cpu-rhel9 (Red Hat AI Inference Server) - F
VulDB
gitpython-developers GitPython up to 3.1.61 Submodule Submodule.update path path traversal
vuldb·2026-09-26·CVSS 5.9
CVE-2026-100689 [MEDIUM] gitpython-developers GitPython up to 3.1.61 Submodule Submodule.update path path traversal
A vulnerability has been found in gitpython-developers GitPython up to 3.1.61 and classified as problematic. This affects the function Submodule.update of the component Submodule. This manipulation of the argument path causes path traversal.
This vulnerability is registered as CVE-2026-100689. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules.
ghsa_unreviewed·2026-09-26
CVE-2026-100689 [HIGH] CWE-22 GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules.
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPython's own containment guard Submodule._to_relative_path() is applied in add() and move(), Submodule.update() derives the absolute checkout location from the raw `path` value without that guard. A .gitmodules entry containing directory traversal components (e.g., path = ../../../tmp/escaped) can therefore cause directories to be created via os.makedirs() outside the repository working tree, populated from the submodule URL on the clone path, and removed via shutil.rmtree() when force_remove is used. Exploitation requires an application flow that updates s
No detection rules found.
No public exploits indexed.
2026-09-26
Published