CVE-2026-67323
published 2026-08-01CVE-2026-67323: GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command…
PriorityP350high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
1.04%
62.2th percentile
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output= can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitpython-developers | gitpython | < 3.1.51 | 3.1.51 |
| gitpython_project | gitpython | < 3.1.51 | 3.1.51 |
| llvm | llvm | — | — |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-p
ghsa_unreviewed·2026-08-01
CVE-2026-67323 [HIGH] CWE-77 GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-p
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output= can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods.
VulDB
gitpython-developers GitPython up to 3.1.50 command injection (EUVD-2026-51805)
vuldb·2026-08-01·CVSS 8.4
CVE-2026-67323 [HIGH] gitpython-developers GitPython up to 3.1.50 command injection (EUVD-2026-51805)
A vulnerability, which was classified as critical, has been found in gitpython-developers GitPython up to 3.1.50. The affected element is the function Repo.archive/git.ls_remote/Repo.iter_commits/Repo.blame. Performing a manipulation results in command injection.
This vulnerability is identified as CVE-2026-67323. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
Red Hat
gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
vendor_redhat·2026-08-01·CVSS 8.4
CVE-2026-67323 [HIGH] CWE-88 gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
A flaw was found in GitPython where it fails to properly sanitize dangerous Git options. This vulnerability allows an attacker to inject arbitrary commands when using functions like Repo.archive() and git.ls_remote(), potentially leading to arbitrary code execution. Additionally, functions such as Repo.iter_commits() and Repo.blame() do not validate revision arguments, which could allow an attacker to truncate arbitrary files. Exploitation requires an application to pass attacker-controlled input directly to these vulnerable methods.
Package: llvm (Red Hat Hardened Images) - Affected
Package: llvm21 (Red Hat Hardened Images) - Affected
Package: rust (Red Hat Hardened Images) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-67323 GitPython: GitPython: Arbitrary code execution via command injection due to unguarded Git options [epel-all]
bugzilla·2026-08-10·CVSS 8.4
CVE-2026-67323 [HIGH] CVE-2026-67323 GitPython: GitPython: Arbitrary code execution via command injection due to unguarded Git options [epel-all]
CVE-2026-67323 GitPython: GitPython: Arbitrary code execution via command injection due to unguarded Git options [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output= can cause Git to open and truncate an arbitrary file. Exploitation require
Bugzilla
CVE-2026-67323 gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
bugzilla·2026-08-01·CVSS 8.4
CVE-2026-67323 [HIGH] CVE-2026-67323 gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
CVE-2026-67323 gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output= can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods.
2026-08-01
Published