<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 09:35:46 +0000</lastBuildDate>
    <item>
      <title>BREW-aider-CVE-2026-67326 — GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-67326</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;Summary&lt;/p&gt;
&lt;p&gt;The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.&lt;/p&gt;
&lt;p&gt;Details&lt;/p&gt;
&lt;p&gt;File: git/config.py — GitPython 3.1.49 (latest patched version)&lt;/p&gt;
&lt;p&gt;```python
  def set_value(self, section: str, option: str, value) -&amp;gt; &amp;#34;GitConfigParser&amp;#34;:
      value_str = self._value_to_string_safe(value)   # only value is validated
      if not self.has_section(section):
          self.add_section(section)                    # section not validated
      super().set(section, option, value_str)          # option not validated
      return self
```&lt;/p&gt;
&lt;p&gt;_write() formats section headers as &amp;#34;[%s]\n&amp;#34; % name. When section = &amp;#34;user]\n[core&amp;#34;, this writes [user]\n[core]\n — two valid section headers — into .git/config.&lt;/p&gt;
&lt;p&gt;PoC&lt;/p&gt;
&lt;p&gt;```python
  import git, os, subprocess&lt;/p&gt;
&lt;p&gt;repo = git.Repo.init(&amp;#34;/tmp/bypass_test&amp;#34;)&lt;/p&gt;
&lt;p&gt;os.makedirs(&amp;#34;/tmp/evil_hooks&amp;#34;, exist_ok=True)
  with open(&amp;#34;/tmp/evil_hooks/pre-commit&amp;#34;, &amp;#34;w&amp;#34;) as f:
      f.write(&amp;#34;#!/bin/sh\nid &amp;gt; /tmp/rce_proof.txt\n&amp;#34;)
  os.chmod(&amp;#34;/tmp/evil_hooks/pre-commit&amp;#34;, 0o755)&lt;/p&gt;
&lt;p&gt;# Inject newline into section parameter (not value — already patched)
  with repo.config_writer() as cw:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;Summary&lt;/p&gt;
&lt;p&gt;The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \n to write arbitrary section headers into .git/config, including a forged [core] section with hooksPath pointing to an attacker-controlled directory, leading to RCE when any git hook is triggered.&lt;/p&gt;
&lt;p&gt;Details&lt;/p&gt;
&lt;p&gt;File: git/config.py — GitPython 3.1.49 (latest patched version)&lt;/p&gt;
&lt;p&gt;```python
  def set_value(self, section: str, option: str, value) -&amp;gt; &amp;#34;GitConfigParser&amp;#34;:
      value_str = self._value_to_string_safe(value)   # only value is validated
      if not self.has_section(section):
          self.add_section(section)                    # section not validated
      super().set(section, option, value_str)          # option not validated
      return self
```&lt;/p&gt;
&lt;p&gt;_write() formats section headers as &amp;#34;[%s]\n&amp;#34; % name. When section = &amp;#34;user]\n[core&amp;#34;, this writes [user]\n[core]\n — two valid section headers — into .git/config.&lt;/p&gt;
&lt;p&gt;PoC&lt;/p&gt;
&lt;p&gt;```python
  import git, os, subprocess&lt;/p&gt;
&lt;p&gt;repo = git.Repo.init(&amp;#34;/tmp/bypass_test&amp;#34;)&lt;/p&gt;
&lt;p&gt;os.makedirs(&amp;#34;/tmp/evil_hooks&amp;#34;, exist_ok=True)
  with open(&amp;#34;/tmp/evil_hooks/pre-commit&amp;#34;, &amp;#34;w&amp;#34;) as f:
      f.write(&amp;#34;#!/bin/sh\nid &amp;gt; /tmp/rce_proof.txt\n&amp;#34;)
  os.chmod(&amp;#34;/tmp/evil_hooks/pre-commit&amp;#34;, 0o755)&lt;/p&gt;
&lt;p&gt;# Inject newline into section parameter (not value — already patched)
  with repo.config_writer() as cw:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-67326</guid>
    </item>
    <item>
      <title>EUVD-2026-352670</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352670</link>
      <description>EUVD-2026-352670</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352670</guid>
    </item>
    <item>
      <title>fkie_cve-2026-67326</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-67326</link>
      <description>&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-67326</guid>
    </item>
    <item>
      <title>GHSA-gmvg-8p66-77hg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gmvg-8p66-77hg</link>
      <description>&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gmvg-8p66-77hg</guid>
    </item>
    <item>
      <title>OESA-2026-3249 — python-GitPython security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3249</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: python-GitPython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process&amp;amp;apos;s environment variables (e.g., AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN). The resulting URL, now containing the secret, is transmitted over the network to an attacker-controlled host during the clone attempt, disclosing the secret.(CVE-2026-67322)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=&amp;amp;lt;path&amp;amp;gt; can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods.(CVE-2026-67323)&lt;/p&gt;
&lt;p&gt;GitPython 3.1.50 fails to recognize joined short-option forms such as -u&amp;amp;lt;value&amp;amp;gt; (the short form of --upload-pack=&amp;amp;lt;value&amp;amp;gt;) when enforcing i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: python-GitPython&lt;/p&gt;
&lt;p&gt;GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process&amp;amp;apos;s environment variables (e.g., AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN). The resulting URL, now containing the secret, is transmitted over the network to an attacker-controlled host during the clone attempt, disclosing the secret.(CVE-2026-67322)&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=&amp;amp;lt;path&amp;amp;gt; can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods.(CVE-2026-67323)&lt;/p&gt;
&lt;p&gt;GitPython 3.1.50 fails to recognize joined short-option forms such as -u&amp;amp;lt;value&amp;amp;gt; (the short form of --upload-pack=&amp;amp;lt;value&amp;amp;gt;) when enforcing i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3249</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11466-1 — python313-GitPython-3.1.58-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11466-1</link>
      <description>&lt;p&gt;python313-GitPython-3.1.58-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-GitPython-3.1.58-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11466-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3980</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3980</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: gitpython&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3980</guid>
    </item>
    <item>
      <title>RHSA-2026:44416 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:44416</link>
      <description>&lt;p&gt;gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation gitpython: GitPython: Remote Code Execution via Newline Injection in config_writer()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options gitpython: GitPython: Command Injection via Git option prefix abbreviation gitpython: GitPython: Remote Code Execution via Newline Injection in config_writer()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:44416</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-67326</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67326</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:Pro:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-git, Ubuntu:Pro:16.04:LTS: python-git, Ubuntu:Pro:18.04:LTS: python-git, Ubuntu:Pro:20.04:LTS: python-git, Ubuntu:Pro:22.04:LTS: python-git, Ubuntu:Pro:24.04:LTS: python-git, Ubuntu:Pro:26.04:LTS: python-git&lt;/p&gt;
&lt;p&gt;GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-67326</guid>
    </item>
  </channel>
</rss>
