<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:17:02.339817+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-87817</id>
    <title>CVE-2026-87817 — GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation</title>
    <updated>2026-10-02T11:17:02.343398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> gitpython-developers GitPython</p>
<p>GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-87817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-239g-whfq-7xj9</id>
    <title>GHSA-239g-whfq-7xj9 — GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution</title>
    <updated>2026-10-02T11:17:02.343486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>### Summary</p>
<p>`Repo.__init__` decides which directory is the git directory by testing candidate paths in an order that
considers the real `.git` **last**. Two earlier tests can be satisfied by ordinary tracked files. Git
reserves only the literal name `.git`, so `HEAD`, `objects/`, `refs/`, `config`, `gitdir`, `commondir`
and `hooks/` at a repository root are all legal tracked content.</p>
<p>Consequently, after a victim opens or clones an attacker's repository, GitPython resolves `git_dir` to
the **working-tree root** while real git correctly resolves `&lt;root&gt;/.git`. Everything GitPython then
treats as "inside the git directory" is attacker-authored content — including `hooks/`, which it
executes.</p>
<p>### CVE-2026-87817</p>
<p>### Affected code (3.1.59)</p>
<p>The discovery loop in `git/repo/base.py` tests, in order:</p>
<p>1. `git/repo/base.py:299` — `isfile(curpath/gitdir)` **and** `isfile(curpath/commondir)` **and** `isfile(curpath/HEAD)`
2. `git/repo/base.py:320` — `is_git_dir(curpath)`
3. `git/repo/base.py:341` — `dotgit = osp.join(curpath, ".git")` ← the real git dir, considered last</p>
<p>`is_git_dir` (`git/repo/fun.py:60`) requires only that `objects/` and `refs/` are directories and that
`HEAD` is a file; **`HEAD`'s contents are never parsed.** The hook path is resolved from
`index.repo.git_dir` (`git/index/fun.py:73`), i.e. the mis-resolved directory.</p>
<p>### Proof of concept</p>
<p>Requires only `pip install GitPython==3.1.59`. Full script attached as `poc1_rce.py`; it runs entirely
in a temp directory an…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-239g-whfq-7xj9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3982</id>
    <title>PYSEC-2026-3982</title>
    <updated>2026-10-02T11:17:02.343613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: gitpython</p>
<p>GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3982"/>
  </entry>
</feed>
