CVE-2026-76218
published 2026-08-19CVE-2026-76218: GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a…
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.72%
52.5th percentile
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| gitpython-developers | gitpython | < 3.1.58 | 3.1.58 |
| gitpython_project | gitpython | < 3.1.58 | 3.1.58 |
| gitpython_project | gitpython | — | — |
| satellite-capsule_el8 | python-gitpython | — | — |
| satellite | iop-vmaas-rhel9 | — | — |
| satellite | iop-vulnerability-engine-rhel9 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gitpython: GitPython: Remote Code Execution via malicious Git hooks
vendor_redhat·2026-08-19·CVSS 7.5
CVE-2026-76218 [HIGH] CWE-94 gitpython: GitPython: Remote Code Execution via malicious Git hooks
gitpython: GitPython: Remote Code Execution via malicious Git hooks
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
A flaw was found in GitPython. This vulnerability allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted template parameter to the `Repo.init` function, an attacker can point to a directory containing malicious Git hooks. When Git operations are performed on the initialized repository, these hooks execute arbitrary code, leading to a complete compromise of the affect
VulDB
gitpython-developers GitPython up to 3.1.57 Repo Init Repo.init template initialization (Nessus ID 338207)
vuldb·2026-09-06·CVSS 8.8
CVE-2026-76218 [HIGH] gitpython-developers GitPython up to 3.1.57 Repo Init Repo.init template initialization (Nessus ID 338207)
A vulnerability classified as critical was found in gitpython-developers GitPython up to 3.1.57. This issue affects the function Repo.init of the component Repo Init. The manipulation of the argument template results in improper initialization.
This vulnerability was named CVE-2026-76218. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
GHSA
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation.
ghsa_unreviewed·2026-08-19
CVE-2026-76218 [HIGH] CWE-88 GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation.
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-76218 GitPython: GitPython: Remote Code Execution via malicious Git hooks [fedora-all]
bugzilla·2026-08-27·CVSS 7.5
CVE-2026-76218 [HIGH] CVE-2026-76218 GitPython: GitPython: Remote Code Execution via malicious Git hooks [fedora-all]
CVE-2026-76218 GitPython: GitPython: Remote Code Execution via malicious Git hooks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
Discussion:
GitPython >=3.1.58 is already in all Fedora branches.
Bugzilla
CVE-2026-76218 GitPython: GitPython: Remote Code Execution via malicious Git hooks [epel-all]
bugzilla·2026-08-27·CVSS 7.5
CVE-2026-76218 [HIGH] CVE-2026-76218 GitPython: GitPython: Remote Code Execution via malicious Git hooks [epel-all]
CVE-2026-76218 GitPython: GitPython: Remote Code Execution via malicious Git hooks [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
Discussion:
GitPython >=3.1.58 is already in all EPEL branches, except EPEL8 where it cannot be updated.
Bugzilla
CVE-2026-76218 gitpython: GitPython: Remote Code Execution via malicious Git hooks
bugzilla·2026-08-19·CVSS 7.5
CVE-2026-76218 [HIGH] CVE-2026-76218 gitpython: GitPython: Remote Code Execution via malicious Git hooks
CVE-2026-76218 gitpython: GitPython: Remote Code Execution via malicious Git hooks
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
2026-08-19
Published