The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
GHSA-239g-whfq-7xj9: GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
- Identifiers
- CVE-2026-87817GHSA-239g-whfq-7xj9
- Published
- Record updated
Summary
GitPython's `Repo.__init__` checks candidate git directories in an order that tests attacker-controllable tracked files at the repository root (`HEAD`, `objects/`, `refs/`, `gitdir`, `commondir`) before the real `.git`, so it resolves `git_dir` to the working-tree root. Affected code is GitPython 3.1.59 (CVE-2026-87817), where a repository opened or cloned with GitPython can make `index.commit()` execute a tracked `hooks/pre-commit`, and a tracked `config` with an `[include]` path can disclose files outside the repository.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.