CVE-2026-69097
published 2026-08-03CVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through…
PriorityP340high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.26%
17.6th percentile
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-25 | hub-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| exploit-intelligence | vulnerability-analysis-rhel9 | — | — |
| gitpython-developers | gitpython | < 3.1.53 | 3.1.53 |
| gitpython_project | gitpython | < 3.1.53 | 3.1.53 |
| gitpython_project | gitpython | — | — |
| mta | mta-solution-server-rhel9 | — | — |
| pen-drive | pen-drive-scanner-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhelai3 | disk-image-cuda-rhel9 | — | — |
| rhoai | odh-feature-server-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
gitpython-developers GitPython up to 3.1.52 Submodule Operations create_submodule/clone_from submodule names code injection (EUVD-2026-52290)
vuldb·2026-09-17·CVSS 7.3
CVE-2026-69097 [HIGH] gitpython-developers GitPython up to 3.1.52 Submodule Operations create_submodule/clone_from submodule names code injection (EUVD-2026-52290)
A vulnerability, which was classified as problematic, has been found in gitpython-developers GitPython up to 3.1.52. The affected element is the function create_submodule/clone_from of the component Submodule Operations. The manipulation of the argument submodule names leads to code injection.
This vulnerability is traded as CVE-2026-69097. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names.
ghsa_unreviewed·2026-08-03
CVE-2026-69097 [HIGH] CWE-74 GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names.
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
Red Hat
gitpython: GitPython: Remote Code Execution via Config Injection in Submodule Names
vendor_redhat·2026-08-03·CVSS 7.0
CVE-2026-69097 [HIGH] CWE-78 gitpython: GitPython: Remote Code Execution via Config Injection in Submodule Names
gitpython: GitPython: Remote Code Execution via Config Injection in Submodule Names
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
A flaw was found in GitPython. This vulnerability allows an attacker to inject malicious configuration directives into Git configuration files by using specially crafted submodule names. This can lead to remote code execution, enabling the attacker to run unauthorized commands on the affected system when Git performs S
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-69097 gitpython: GitPython: Remote Code Execution via Config Injection in Submodule Names
bugzilla·2026-08-03·CVSS 7.0
CVE-2026-69097 [HIGH] CVE-2026-69097 gitpython: GitPython: Remote Code Execution via Config Injection in Submodule Names
CVE-2026-69097 gitpython: GitPython: Remote Code Execution via Config Injection in Submodule Names
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
Wiz
CVE-2025-69097 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-69097 [HIGH] CVE-2025-69097 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69097 :
WordPress vulnerability analysis and mitigation
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through <= 1.9.9.5.4.
Source : NVD
## 8.1
Score
Published January 22, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
wplms_plugin
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Wor
2026-08-03
Published