CVE-2026-44244
published 2026-05-07CVE-2026-44244: GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
14.9th percentile
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path. This issue has been patched in version 3.1.49.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| gitpython-developers | gitpython | < 3.1.49 | 3.1.49 |
| gitpython_project | gitpython | < 3.1.49 | 3.1.49 |
| gitpython_project | gitpython | — | — |
| gitpython_project | gitpython | >= 0 < 3.1.49 | 3.1.49 |
| pen-drive | pen-drive-scanner-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhelai3 | disk-image-cuda-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GitPython vulnerabilities
vendor_ubuntu·2026-05-26·CVSS 6.5
CVE-2026-42215 [MEDIUM] GitPython vulnerabilities
Title: GitPython vulnerabilities
Summary: Several security issues were fixed in GitPython.
Santos Gallegos discovered that GitPython did not properly validate
paths when resolving certain Git references. An attacker could possibly
use this issue to cause files outside the .git directory to be accessed,
leading to a denial of service. This issue only affected Ubuntu 14.04
LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS. (CVE-2023-41040)
Wes Ring discovered that GitPython did not properly block certain unsafe
Git options when they were provided as Python keyword arguments. An
attacker could possibly use this issue to cause arbitrary command
execution. (CVE-2026-42215)
It was discovered that GitPython did not properly validate clone options
before processin
Red Hat
GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
vendor_redhat·2026-05-07·CVSS 7.8
CVE-2026-44244 [HIGH] CWE-1286 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path. This issue has been patched in version 3.1.49.
A flaw was found in GitPython, a Python library used to interact with Git repositories. The `GitCon
VulDB
gitpython-developers GitPython up to 3.1.48 GitConfigParser.set_value code injection (GHSA-v87r-6q3f-2j67)
vuldb·2026-05-07·CVSS 7.8
CVE-2026-44244 [HIGH] gitpython-developers GitPython up to 3.1.48 GitConfigParser.set_value code injection (GHSA-v87r-6q3f-2j67)
A vulnerability identified as critical has been detected in gitpython-developers GitPython up to 3.1.48. This issue affects the function GitConfigParser.set_value. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-44244. Local access is required to approach this attack. No exploit exists.
You should upgrade the affected component.
GHSA
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
ghsa·2026-05-06
CVE-2026-44244 [HIGH] CWE-94 GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
`GitConfigParser.set_value()` passes values to Python's `configparser` without validating for newlines. GitPython's own `_write()` converts embedded newlines into indented continuation lines (e.g. `\n` becomes `\n\t`), but Git still accepts an indented `[core]` stanza as a section header — so the injected `core.hooksPath` becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path.
The vulnerability is not merely malformed config output: GitPython's own writer converts embedded newlines into indented continuation lines, but Git still accepts an indented `[core]` stanza as a section header, so the injecte
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [fedora-44]
bugzilla·2026-08-17·CVSS 7.8
CVE-2026-44244 [HIGH] CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [fedora-44]
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [fedora-44]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation t
Bugzilla
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [fedora-43]
bugzilla·2026-08-17·CVSS 7.8
CVE-2026-44244 [HIGH] CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [fedora-43]
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation t
Bugzilla
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [epel-all]
bugzilla·2026-08-14·CVSS 7.8
CVE-2026-44244 [HIGH] CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [epel-all]
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation th
Bugzilla
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
bugzilla·2026-05-07·CVSS 7.8
CVE-2026-44244 [HIGH] CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
CVE-2026-44244 GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as a section header — so the injected core.hooksPath becomes effective configuration. Any Git operation that invokes hooks (commit, merge, checkout) will then execute scripts from the attacker-controlled path. This issue has been patched in version 3.1.49.
2026-05-07
Published