CVE-2026-69097

NameCVE-2026-69097
DescriptionGitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1143602

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-git (PTS)bookworm3.1.30-1+deb12u2vulnerable
trixie3.1.44-1vulnerable
forky, sid3.1.61-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-gitsource(unstable)3.1.61-11143602

Notes

[trixie] - python-git <no-dsa> (Minor issue)
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2

Search for package or bug name: Reporting problems