Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-67326— GitPython before 3.1.50 Newline Injection via config_writer section

CVSS 7.0 · High EPSS 0.19% · P9

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProductVersion RangeStatus
gitpython-developersGitPython< 3.1.50affected
3.1.50unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-67326

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GitPython before 3.1.50 Newline Injection via config_writer section
Source: CVE Program / CVE List V5
Vulnerability Description
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
gitpython-developers GitPython 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
gitpython-developers GitPython是gitpython-developers组织的数据库系统。 gitpython-developers GitPython 3.1.50之前版本存在输入验证错误漏洞,该漏洞源于config_writer()的section参数未验证换行符,可能允许攻击者注入任意section头,创建指向攻击者控制目录的伪造[core]节,导致在git hooks触发时实现远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
gitpython-developersGitPython 0 ~ 3.1.50 -

II. Public POCs for CVE-2026-67326

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67326

登录查看更多情报信息。

Vendor Advisories for CVE-2026-67326 (2)

Same Patch Batch · gitpython-developers · 2026-08-01 · 5 CVEs total

CVE-2026-673249.8 CRITICALGitPython 3.1.50 Authentication Bypass via Joined Short Options
CVE-2026-673258.8 HIGHGitPython before 3.1.51 Command Injection via option prefix abbreviation
CVE-2026-673238.4 HIGHGitPython before 3.1.51 Command Injection via unguarded Git options
CVE-2026-673227.5 HIGHGitPython before 3.1.52 Environment Variable Exfiltration via clone_from

IV. Related Vulnerabilities

V. Comments for CVE-2026-67326

No comments yet


Leave a comment