cbcvebase.
CVE-2026-73622
published 2026-08-13

CVE-2026-73622: GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate…

PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.35%
28.9th percentile
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-24controller-rhel8——
ansible-automation-platform-24hub-rhel8——
ansible-automation-platform-25controller-rhel8——
ansible-automation-platform-25hub-rhel8——
ansible-automation-platform-26controller-rhel9——
ansible-automation-platform-26hub-rhel9——
ansible-automation-platform-27controller-rhel9——
ansible-automation-platform-27hub-rhel9——
exploit-intelligence-tech-previewvulnerability-analysis-rhel9——
gitpython-developersgitpython< 3.1.553.1.55
gitpython_projectgitpython< 3.1.553.1.55
gitpython_projectgitpython——
mtamta-solution-server-rhel9——
pen-drivepen-drive-scanner-rhel9——
rhaiisvllm-cpu-rhel9——
rhaiisvllm-tpu-rhel9——
rhelai3bootc-cuda-rhel9——
rhelai3bootc-gaudi-rhel9——
rhelai3bootc-rocm-rhel9——
rhelai3disk-image-cuda-rhel9——
rhoaiodh-feature-server-rhel9——
rhoaiodh-mlflow-rhel9——
rhoaiodh-pipeline-runtime-datascience-cpu-py312-rhel9——
rhoaiodh-pipeline-runtime-pytorch-cuda-py312-rhel9——
rhoaiodh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9——

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.