CVE-2026-67325
published 2026-08-01CVE-2026-67325: GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.85%
78.1th percentile
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitpython-developers | gitpython | < 3.1.51 | 3.1.51 |
| gitpython_project | gitpython | < 3.1.51 | 3.1.51 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature.
ghsa_unreviewed·2026-08-01
CVE-2026-67325 [HIGH] CWE-78 GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature.
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
VulDB
gitpython-developers GitPython up to 3.1.50 command injection
vuldb·2026-08-01·CVSS 8.8
CVE-2026-67325 [HIGH] gitpython-developers GitPython up to 3.1.50 command injection
A vulnerability was found in gitpython-developers GitPython up to 3.1.50 and classified as critical. This impacts an unknown function. The manipulation results in command injection.
This vulnerability is cataloged as CVE-2026-67325. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
Red Hat
gitpython: GitPython: Command Injection via Git option prefix abbreviation
vendor_redhat·2026-08-01·CVSS 8.8
CVE-2026-67325 [HIGH] CWE-78 gitpython: GitPython: Command Injection via Git option prefix abbreviation
gitpython: GitPython: Command Injection via Git option prefix abbreviation
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
A flaw was found in GitPython. This vulnerability stems from an incomplete command injection blocklist that fails to account for Git's long-option prefix abbreviation feature. An attacker can bypass existing security measures by using abbreviated option names, which Git then resolves to dangerous options. This allows for the execution of arbitrary commands, leading to potential arb
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-67325 GitPython: GitPython: Command Injection via Git option prefix abbreviation [epel-all]
bugzilla·2026-08-10·CVSS 8.8
CVE-2026-67325 [HIGH] CVE-2026-67325 GitPython: GitPython: Command Injection via Git option prefix abbreviation [epel-all]
CVE-2026-67325 GitPython: GitPython: Command Injection via Git option prefix abbreviation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
Bugzilla
CVE-2026-67325 gitpython: GitPython: Command Injection via Git option prefix abbreviation
bugzilla·2026-08-01·CVSS 8.8
CVE-2026-67325 [HIGH] CVE-2026-67325 gitpython: GitPython: Command Injection via Git option prefix abbreviation
CVE-2026-67325 gitpython: GitPython: Command Injection via Git option prefix abbreviation
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
2026-08-01
Published