CVE-2026-76221
Last modified
CVE-2026-76221 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via core.sshCommand or core.hooksPath on the next git operation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitpython Project | Gitpython | < 3.1.58 |
References
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgrExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-76221?
How severe is CVE-2026-76221?
How do I fix CVE-2026-76221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76215phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility c…5.3
- CVE-2026-76216Vikunja through 2.4.0 contains a principal-type confusion vu…7.5
- CVE-2026-76217GitPython versions before 3.1.58 fail to validate options pa…6.5
- CVE-2026-76218GitPython before 3.1.58 contains a remote code execution vul…8.8
- CVE-2026-76219GitPython versions before 3.1.58 contain an arbitrary file o…8.1
- CVE-2026-76220GitPython before 3.1.58 contains a command execution vulnera…8.8
- CVE-2026-76222GitPython before 3.1.58 fails to validate submodule names fr…8.2
- CVE-2026-76223ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to …7.1
- CVE-2026-76224ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3…8.8
- CVE-2026-76225ArcadeDB before 26.8.1 contains a server-side request forger…7.7
- CVE-2026-76226Renovate versions from 43.65.0 before 43.102.11 contain a re…6.3
- CVE-2026-76227Renovate versions from 42.68.1 before 42.96.3 (and from 42.6…5.5
Are you affected by CVE-2026-76221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
