[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-78676":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-24T22:49:06.576Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":39,"aliases":40,"duplicate_of":9,"upstream":41,"downstream":42,"duplicates":43,"related":44,"reserved_at":9,"published_at":45,"modified_at":45,"state":46,"summary":47,"references_raw":54,"kevs":66,"epss":9,"epss_history":67,"metrics":68,"affected":80},"CVE-2026-78676","GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-88","Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')","The product constructs a string for a command to be executed by a separate component\nin another control sphere, but it does not properly delimit the\nintended arguments, options, or switches within that command string.","weakness","Draft","Base",[19,23,27,31,35],{"id":20,"name":21,"techniques":22},"CAPEC-137","Parameter Injection",[],{"id":24,"name":25,"techniques":26},"CAPEC-174","Flash Parameter Injection",[],{"id":28,"name":29,"techniques":30},"CAPEC-41","Using Meta-characters in E-mail Headers to Inject Malicious Payloads",[],{"id":32,"name":33,"techniques":34},"CAPEC-460","HTTP Parameter Pollution (HPP)",[],{"id":36,"name":37,"techniques":38},"CAPEC-88","OS Command Injection",[],[],[],[],[],[],[],"2026-08-25T01:30:33.754Z","Received",{"cisa_kev":48,"cisa_ransomware":48,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":49,"severity_score":50,"severity_version":51,"severity_source":52,"severity_vector":53,"severity_status":46},false,"critical",9.8,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[55,61],{"url":56,"sources":57,"tags":59},"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-284h-m62q-gf8w",[52,58],"nvd",[60],"Vendor Advisory",{"url":62,"sources":63,"tags":64},"https://www.vulncheck.com/advisories/gitpython-before-remote-code-execution-via-config-injection",[52,58],[65],"Third Party Advisory",[],[],[69,76],{"source":52,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":70,"cvss_v4_0":73},{"baseScore":50,"baseSeverity":71,"vectorString":53,"impactScore":50,"exploitabilityScore":72},"CRITICAL",10,{"baseScore":74,"baseSeverity":71,"vectorString":75,"impactScore":9,"exploitabilityScore":9},9.3,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",{"source":58,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":77,"cvss_v4_0":78},{"baseScore":50,"baseSeverity":71,"vectorString":53,"impactScore":50,"exploitabilityScore":72},{"baseScore":74,"baseSeverity":71,"vectorString":79,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[81],{"ecosystem":9,"name":82,"vendor":83,"product":84,"cpe_part":85,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":86},"GitPython","gitpython-developers","gitpython","a",[87],{"version":88,"is_range":89,"range_type":52,"version_start":9,"version_start_type":9,"version_end":90,"version_end_type":91,"fixed_in":9},"\u003C 3.1.59",true,"3.1.59","excluding"]