CVE-2026-69097

NameCVE-2026-69097
DescriptionGitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1143602

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-git (PTS)bullseye3.1.14-1vulnerable
bullseye (security)3.1.14-1+deb11u1vulnerable
bookworm3.1.30-1+deb12u2vulnerable
trixie3.1.44-1vulnerable
forky, sid3.1.50-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-gitsource(unstable)(unfixed)1143602

Notes

[trixie] - python-git <no-dsa> (Minor issue)
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2

Search for package or bug name: Reporting problems