CVE-2026-76217
Last modified
CVE-2026-76217 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitpython Project | Gitpython | < 3.1.58 |
References
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfcExploit, Vendor Advisory
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfcExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-76217?
How severe is CVE-2026-76217?
How do I fix CVE-2026-76217?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76211phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATIO…4.3
- CVE-2026-76212phpMyFAQ before 4.1.7, when configured to use PostgreSQL via…5.3
- CVE-2026-76213phpMyFAQ before 4.1.7 contains a brute-force vulnerability i…7.4
- CVE-2026-76214phpMyFAQ before 4.1.7 fails to persist the WebAuthn login ch…7.4
- CVE-2026-76215phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility c…5.3
- CVE-2026-76216Vikunja through 2.4.0 contains a principal-type confusion vu…7.5
- CVE-2026-76218GitPython before 3.1.58 contains a remote code execution vul…8.8
- CVE-2026-76219GitPython versions before 3.1.58 contain an arbitrary file o…8.1
- CVE-2026-76220GitPython before 3.1.58 contains a command execution vulnera…8.8
- CVE-2026-76221GitPython before 3.1.58 contains a config-name injection vul…8.8
- CVE-2026-76222GitPython before 3.1.58 fails to validate submodule names fr…8.2
- CVE-2026-76223ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to …7.1
Are you affected by CVE-2026-76217?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
