<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:54:10.459214+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14474</id>
    <title>bdu:2026-14474</title>
    <updated>2026-10-02T10:54:10.605464+00:00</updated>
    <content>bdu:2026-14474</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-87817</id>
    <title>BREW-aider-CVE-2026-87817 — GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution</title>
    <updated>2026-10-02T10:54:10.605517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>### Summary</p>
<p>`Repo.__init__` decides which directory is the git directory by testing candidate paths in an order that
considers the real `.git` **last**. Two earlier tests can be satisfied by ordinary tracked files. Git
reserves only the literal name `.git`, so `HEAD`, `objects/`, `refs/`, `config`, `gitdir`, `commondir`
and `hooks/` at a repository root are all legal tracked content.</p>
<p>Consequently, after a victim opens or clones an attacker's repository, GitPython resolves `git_dir` to
the **working-tree root** while real git correctly resolves `&lt;root&gt;/.git`. Everything GitPython then
treats as "inside the git directory" is attacker-authored content — including `hooks/`, which it
executes.</p>
<p>### CVE-2026-87817</p>
<p>### Affected code (3.1.59)</p>
<p>The discovery loop in `git/repo/base.py` tests, in order:</p>
<p>1. `git/repo/base.py:299` — `isfile(curpath/gitdir)` **and** `isfile(curpath/commondir)` **and** `isfile(curpath/HEAD)`
2. `git/repo/base.py:320` — `is_git_dir(curpath)`
3. `git/repo/base.py:341` — `dotgit = osp.join(curpath, ".git")` ← the real git dir, considered last</p>
<p>`is_git_dir` (`git/repo/fun.py:60`) requires only that `objects/` and `refs/` are directories and that
`HEAD` is a file; **`HEAD`'s contents are never parsed.** The hook path is resolved from
`index.repo.git_dir` (`git/index/fun.py:73`), i.e. the mis-resolved directory.</p>
<p>### Proof of concept</p>
<p>Requires only `pip install GitPython==3.1.59`. Full script attached as `poc1_rce.py`; it runs entirely
in a temp directory an…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-87817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366298</id>
    <title>EUVD-2026-366298</title>
    <updated>2026-10-02T10:54:10.605596+00:00</updated>
    <content>EUVD-2026-366298</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-87817</id>
    <title>fkie_cve-2026-87817</title>
    <updated>2026-10-02T10:54:10.605612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-87817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-239g-whfq-7xj9</id>
    <title>GHSA-239g-whfq-7xj9 — GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution</title>
    <updated>2026-10-02T10:54:10.605636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>### Summary</p>
<p>`Repo.__init__` decides which directory is the git directory by testing candidate paths in an order that
considers the real `.git` **last**. Two earlier tests can be satisfied by ordinary tracked files. Git
reserves only the literal name `.git`, so `HEAD`, `objects/`, `refs/`, `config`, `gitdir`, `commondir`
and `hooks/` at a repository root are all legal tracked content.</p>
<p>Consequently, after a victim opens or clones an attacker's repository, GitPython resolves `git_dir` to
the **working-tree root** while real git correctly resolves `&lt;root&gt;/.git`. Everything GitPython then
treats as "inside the git directory" is attacker-authored content — including `hooks/`, which it
executes.</p>
<p>### CVE-2026-87817</p>
<p>### Affected code (3.1.59)</p>
<p>The discovery loop in `git/repo/base.py` tests, in order:</p>
<p>1. `git/repo/base.py:299` — `isfile(curpath/gitdir)` **and** `isfile(curpath/commondir)` **and** `isfile(curpath/HEAD)`
2. `git/repo/base.py:320` — `is_git_dir(curpath)`
3. `git/repo/base.py:341` — `dotgit = osp.join(curpath, ".git")` ← the real git dir, considered last</p>
<p>`is_git_dir` (`git/repo/fun.py:60`) requires only that `objects/` and `refs/` are directories and that
`HEAD` is a file; **`HEAD`'s contents are never parsed.** The hook path is resolved from
`index.repo.git_dir` (`git/index/fun.py:73`), i.e. the mis-resolved directory.</p>
<p>### Proof of concept</p>
<p>Requires only `pip install GitPython==3.1.59`. Full script attached as `poc1_rce.py`; it runs entirely
in a temp directory an…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-239g-whfq-7xj9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4025</id>
    <title>OESA-2026-4025 — python-GitPython security update</title>
    <updated>2026-10-02T10:54:10.605696+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-GitPython</p>
<p>**GitPython*is a python library used to interact with Git repositories.GitPython provides object model read and write access to your git repository. Access repository information conveniently, alter the index directly, handle remotes, or go down to low-level object database access with big-files support.With the new object database abstraction added in 0.3, its even possible to implement your own storage mechanisms, the currently available implementations are &amp;amp;apos;cgit&amp;amp;apos; and pure python, which is the default.Documentation The latest documentation can be found here: As this version of GitPython depends on GitDB, which in turn needs smmap to work, installation is a bit more involved if you do a manual installation, instead of using pip.

Security Fix(es):</p>
<p>GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.(CVE-2026-87817)</p>
<p>GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-lin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1</id>
    <title>openSUSE-SU-2026:21874-1 — Security update for python-GitPython</title>
    <updated>2026-10-02T10:54:10.605731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-GitPython</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21874-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3982</id>
    <title>PYSEC-2026-3982</title>
    <updated>2026-10-02T10:54:10.605761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3982"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:68764</id>
    <title>RHSA-2026:68764 — Red Hat Security Advisory: Technical preview of the satellite/iop-vmaas-rhel9 container image</title>
    <updated>2026-10-02T10:54:10.605780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>net/mail: golang: Go net/mail: Denial of Service via crafted email inputs GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks GitPython: GitPython: Arbitrary code execution via improper validation of clone options net/mail: golang: net/mail: Denial of Service via pathological email address parsing GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration openssl: openssl-src: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding gitpython: GitPython: Information disclosure via environment variable expansion in URL handling gitpython: GitPython: Remote Code Execution via malicious Git template gitpython: GitPython: Arbitrary File Overwrite via improper git option validation gitpython: GitPython: Remote Code Execution via kwarg value smuggling gitpython: GitPython: Remote Code Execution via malicious Git hooks gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection gitpython: GitPython: Arbitrary command execution via crafted kwargs gitpython: GitPython: Arbitrary code execution via config-name injection gitpython: G…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:68764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87817</id>
    <title>UBUNTU-CVE-2026-87817</title>
    <updated>2026-10-02T10:54:10.605836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:Pro:26.04:LTS: python-git</p>
<p>GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555</id>
    <title>WID-SEC-W-2026-3555 — Red Hat Ansible Automation Platform (automation-controller): Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:54:10.605866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen und einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3555"/>
  </entry>
</feed>
