CVE-2026-76219
published 2026-08-19CVE-2026-76219: GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods…
PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
0.30%
22.6th percentile
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| gitpython-developers | gitpython | < 3.1.58 | 3.1.58 |
| gitpython_project | gitpython | < 3.1.58 | 3.1.58 |
| gitpython_project | gitpython | — | — |
| satellite-capsule_el8 | python-gitpython | — | — |
| satellite | iop-vmaas-rhel9 | — | — |
| satellite | iop-vulnerability-engine-rhel9 | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv4.07.2HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection
vendor_redhat·2026-08-19·CVSS 8.1
CVE-2026-76219 [HIGH] CWE-88 gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection
gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
A flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, and `IndexFile.merge_tree`,
GHSA
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strin
ghsa_unreviewed·2026-08-19
CVE-2026-76219 [HIGH] CWE-88 GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strin
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-76219 GitPython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection [epel-all]
bugzilla·2026-08-27·CVSS 8.1
CVE-2026-76219 [HIGH] CVE-2026-76219 GitPython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection [epel-all]
CVE-2026-76219 GitPython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
Discussion:
Git
Bugzilla
CVE-2026-76219 GitPython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection [fedora-all]
bugzilla·2026-08-27·CVSS 8.1
CVE-2026-76219 [HIGH] CVE-2026-76219 GitPython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection [fedora-all]
CVE-2026-76219 GitPython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
Discussion:
G
Bugzilla
CVE-2026-76219 gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection
bugzilla·2026-08-19·CVSS 8.1
CVE-2026-76219 [HIGH] CVE-2026-76219 gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection
CVE-2026-76219 gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths.
2026-08-19
Published