CVE-2026-42215
published 2026-05-07CVE-2026-42215: GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such…
PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.90%
57.9th percentile
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| gitpython-developers | gitpython | — | — |
| gitpython_project | gitpython | >= 0 < 3.1.54 | 3.1.54 |
| gitpython_project | gitpython | >= 0 < 3.1.51 | 3.1.51 |
| gitpython_project | gitpython | >= 0 < 3.1.59 | 3.1.59 |
| gitpython_project | gitpython | >= 0 < 3.1.50 | 3.1.50 |
| gitpython_project | gitpython | 0 – 3.1.50 | — |
| gitpython_project | gitpython | >= 3.1.30 < 3.1.47 | 3.1.47 |
| gitpython_project | gitpython | >= 3.1.30 < 3.1.47 | 3.1.47 |
| gitpython_project | gitpython | >= 3.1.50 < 3.1.51 | 3.1.51 |
| mta | mta-solution-server-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhelai3 | disk-image-cuda-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for use of Python kwargs `upload_pack` or `receive_pack` passed into GitPython methods (Repo.clone_from(), Remote.fetch(), Remote.pull(), Remote.push()) as these bypass the allow_unsafe_options=False default check ↗
- →Flag GitPython versions 3.1.30 through 3.1.46 (inclusive) as vulnerable; enforce upgrade to 3.1.47 or later ↗
- ·The dangerous Git options `--upload-pack` and `--receive-pack` are blocked by default, but their Python kwarg equivalents (`upload_pack`, `receive_pack`) are NOT blocked — the bypass works regardless of the `allow_unsafe_options` setting ↗
- ·The vulnerability is only exploitable when an application passes attacker-controlled kwargs into the affected GitPython methods; applications that do not expose kwargs to user input are not directly at risk ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
ghsa·2026-09-08·CVSS 8.8
CVE-2026-78679 [HIGH] CWE-88 GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f's tag instance).
## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = ["--file","-F"]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects
GHSA
Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
ghsa·2026-08-01·CVSS 8.8
CVE-2026-42215 [HIGH] CWE-78 Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2f96-g7mh-g2hx. This link is maintained to preserve external references.
## Original Description
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
GHSA
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
ghsa·2026-07-24·CVSS 8.8
CVE-2026-42215 [HIGH] CWE-78 GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
## Summary
GitPython's `check_unsafe_options` guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for **every** guarded method (`clone`/`clone_from`, `fetch`/`pull`/`push`, `ls_remote`, `iter_commits`, `blame`, `archive`) by smuggling an option token inside the VALUE of a single-character kwarg. In the default `allow_unsafe_options=False` configuration this yields arbitrary command execution via `--upload-pack`.
## Root Cause
The guard builds its candidate option list from kwarg KEYS only: `_option_candidates([], {"n":"--upload-pack="})` returns `['-n']` (cmd.py:1042-1046 derives the candidate from the key, never the va
GHSA
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
ghsa·2026-07-21·CVSS 8.8
CVE-2026-42215 [HIGH] CWE-184 GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)
**Component:** gitpython-developers/GitPython (PyPI: GitPython)
**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (verified at commit `20c5e275`, `3.1.50-42`)
**CWE:** CWE-184 (Incomplete List of Disallowed Inputs) → CWE-78 (OS Command Injection)
**Severity:** inherits the parent CVE-2026-42215 surface; estimated High, ~8.8 (`AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`) — final scoring deferred to maintainer/CNA, mirroring the parent.
**Reporter:** hackkim
### Summary
The 3.1.47 fix for CVE-2026-42215 blocks dan
GHSA
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
ghsa·2026-07-21
CVE-2026-42215 [HIGH] CWE-77 GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
## Summary
GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`--upload-pack`, `--receive-pack`, `--exec`, `-c`, `--config`, …) that can be abused to run arbitrary commands, and enforces them with `Git.check_unsafe_options()`.
That enforcement is only wired into the **network** commands — `clone_from`, `Remote.fetch`, `Remote.pull`, `Remote.push`. Several other public APIs that also forward caller-controlled values into the `git` argv have **no guard at all**:
1. **`Repo.archive(ostream, tre
GHSA
GitPython unsafe clone option gate bypass through joined short options
ghsa·2026-07-21
CVE-2026-42284 [HIGH] CWE-78 GitPython unsafe clone option gate bypass through joined short options
GitPython unsafe clone option gate bypass through joined short options
`GitPython` version `3.1.50` blocks unsafe `git clone` options such as `--upload-pack`, `-u`, `--config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/helper`.
Git itself accepts `-u` as the short form of `--upload-pack=`. As a result, `Repo.clone_from(..., multi_options=["-u"], allow_unsafe_options=False)` can execute the helper command even though the equivalent long option is blocked.
Affected package:
- Ecosystem: PyPI
- Package: `GitPython`
- Confirmed affected version: `3.1.50`
- Repository: `gitpython-developers/GitPython`
- Current PyPI version during triage: `3.1.50`
Relevant beh
GHSA
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
ghsa·2026-05-08·CVSS 8.8
CVE-2026-42215 [HIGH] CWE-20 GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
Summary
The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.
Details
File: git/config.py — GitPython 3.1.49 (latest patched version)
```python
def set_value(self, section: str, option: str, value) -> "GitConfigParser":
value_str = self._value_to_string_safe(va
VulDB
gitpython-developers GitPython up to 3.1.46 os command injection
vuldb·2026-05-07·CVSS 8.8
CVE-2026-42215 [HIGH] gitpython-developers GitPython up to 3.1.46 os command injection
A vulnerability, which was classified as critical, was found in gitpython-developers GitPython up to 3.1.46. This affects the function Repo.clone_from/Remote.fetch/Remote.pull/Remote.push. Executing a manipulation can lead to os command injection.
This vulnerability is registered as CVE-2026-42215. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
GHSA
GitPython has Command Injection via Git options bypass
ghsa·2026-04-25
CVE-2026-42215 [HIGH] CWE-78 GitPython has Command Injection via Git options bypass
GitPython has Command Injection via Git options bypass
### Summary
GitPython blocks dangerous Git options such as `--upload-pack` and `--receive-pack` by default, but the equivalent Python kwargs `upload_pack` and `receive_pack` bypass that check. If an application passes attacker-controlled kwargs into `Repo.clone_from()`, `Remote.fetch()`, `Remote.pull()`, or `Remote.push()`, this leads to arbitrary command execution even when `allow_unsafe_options` is left at its default value of `False`.
### Details
GitPython explicitly treats helper-command options as unsafe because they can be used to execute arbitrary commands:
- `git/repo/base.py:145-153` marks clone options such as `--upload-pack`, `-u`, `--config`, and `-c` as unsafe.
- `git/remote.py:535-548` marks fetch/pull/push options suc
Ubuntu
GitPython vulnerabilities
vendor_ubuntu·2026-05-26·CVSS 6.5
CVE-2026-42215 [MEDIUM] GitPython vulnerabilities
Title: GitPython vulnerabilities
Summary: Several security issues were fixed in GitPython.
Santos Gallegos discovered that GitPython did not properly validate
paths when resolving certain Git references. An attacker could possibly
use this issue to cause files outside the .git directory to be accessed,
leading to a denial of service. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS. (CVE-2023-41040)
Wes Ring discovered that GitPython did not properly block certain unsafe
Git options when they were provided as Python keyword arguments. An
attacker could possibly use this issue to cause arbitrary command
execution. (CVE-2026-42215)
It was discovered that GitPython did not properly validate clone options
before processin
Red Hat
GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
vendor_redhat·2026-05-07·CVSS 8.8
CVE-2026-42215 [HIGH] CWE-88 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.
A flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows an attacker to a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks [fedora-44]
bugzilla·2026-08-17·CVSS 8.8
CVE-2026-42215 [HIGH] CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks [fedora-44]
CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks [fedora-44]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execut
Bugzilla
CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks [fedora-43]
bugzilla·2026-08-17·CVSS 8.8
CVE-2026-42215 [HIGH] CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks [fedora-43]
CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execut
Bugzilla
CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
bugzilla·2026-05-07·CVSS 8.8
CVE-2026-42215 [HIGH] CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
CVE-2026-42215 GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47.
2026-05-07
Published