CVE-2026-87817
published 2026-09-09CVE-2026-87817: GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like…
PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.40%
31.9th percentile
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-25 | hub-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| exploit-intelligence | vulnerability-analysis-rhel9 | — | — |
| gitpython-developers | gitpython | < 3.1.60 | 3.1.60 |
| gitpython_project | gitpython | < 3.1.60 | 3.1.60 |
| gitpython_project | gitpython | — | — |
| mta | mta-solution-server-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhelai3 | disk-image-cuda-rhel9 | — | — |
| rhoai | odh-feature-server-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
GitPython: GitPython: Remote Code Execution via Git directory impersonation
vendor_redhat·2026-09-09·CVSS 8.8
CVE-2026-87817 [HIGH] CWE-22 GitPython: GitPython: Remote Code Execution via Git directory impersonation
GitPython: GitPython: Remote Code Execution via Git directory impersonation
A flaw was found in GitPython. This vulnerability allows a remote attacker to execute arbitrary code. By failing to properly validate the git directory location, GitPython allows attackers to impersonate the git directory using tracked files such as gitdir, commondir, and HEAD. An attacker can then place a malicious pre-commit hook in the tracked hooks directory, which executes when a victim calls index.commit() on a cloned or opened repository.
Package: exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 (Exploit Intelligence) - Under investigation
Package: exploit-intelligence/vulnerability-analysis-rhel9 (Exploit Intelligence) - Under investigation
Package: mta/mta-solution-server-rhel9 (Migration
GHSA
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD.
ghsa_unreviewed·2026-09-09
CVE-2026-87817 [HIGH] CWE-94 GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD.
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation [fedora-all]
bugzilla·2026-09-10·CVSS 8.8
CVE-2026-87817 [HIGH] CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation [fedora-all]
CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
Discussion:
This is fixed in 3.1.60, which is already in all Fedora branches, EPEL10, and EPE
Bugzilla
CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation [epel-all]
bugzilla·2026-09-10·CVSS 8.8
CVE-2026-87817 [HIGH] CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation [epel-all]
CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
Discussion:
This is fixed in 3.1.60, which is already in all Fedora branches, EPEL10, and EPEL9
Bugzilla
CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-87817 [HIGH] CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation
CVE-2026-87817 GitPython: GitPython: Remote Code Execution via Git directory impersonation
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
2026-09-09
Published