A high-severity vulnerability affecting gitpython versions <= 3.1.59 (CVSS score of 8.8) exists in the GitPython library, specifically in its discovery loop for determining the git directory. This flaw allows an attacker to execute arbitrary commands via tracked hooks when a victim opens or clones an untrusted repository with GitPython. The issue arises from the fact that GitPython considers the working-tree root as the git directory instead of the real.git directory, allowing an attacker to manipulate content within the repository. This can lead to code execution, reading files outside the repository, and writing a config file to an attacker-chosen directory. The vulnerability is silent and affects services that open or clone untrusted repositories with GitPython, including CI runners, code-scanning/SBOM services, mirrors, dependency bots, and AI code-review/agent tools.
We recommend you to update GitPython to version 3.1.60.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting gitpython versions <= 3.1.59 (CVSS score of 8.8) exists in the GitPython library, specifically in its discovery loop for determining the git directory. This flaw allows an attacker to execute arbitrary commands via tracked hooks when a victim opens or clones an untrusted repository with GitPython. The issue arises from the fact that GitPython considers the working-tree root as the git directory instead of the real.git directory, allowing an attacker to manipulate content within the repository. This can lead to code execution, reading files outside the repository, and writing a config file to an attacker-chosen directory. The vulnerability is silent and affects services that open or clone untrusted repositories with GitPython, including CI runners, code-scanning/SBOM services, mirrors, dependency bots, and AI code-review/agent tools.
We recommend you to update GitPython to version 3.1.60.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]