SUSE-SU-2026:4072-1

Advisory lineage Upstream: 27 Downstream: 0
Published: 08 Sept 2026, 07:07
Last modified:13 Sept 2026, 18:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Sept 2026, 07:07
Published
Vulnerability first disclosed
13 Sept 2026, 18:23
Last Modified
Vulnerability information updated

Description

Security update for python-GitPython This update for python-GitPython fixes the following issues: - CVE-2026-42215: command injection via Git options bypass (bsc#1264604). - CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605). - CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository (bsc#1264606). - CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608). - CVE-2026-67322: vulnerable to environment-variable exfiltration in Repo.clone_from() (bsc#1273357). - CVE-2026-67323: fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote() (bsc#1273358). - CVE-2026-67325: contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature (bsc#1273359). - CVE-2026-67326: fails to validate newline characters in the section parameter of config_writer() (bsc#1273364). - CVE-2026-69097: fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names (bsc#1273414). - CVE-2026-73619: incomplete denylist in the `unsafe_git_archive_options` guard that omits `--add-file` and `--add- virtual-file` options can lead to arbitrary file reads (bsc#1275755). - CVE-2026-73620: failure to guard git option forwarding in `IndexFile.checkout()` and `TagReference.create()` can lead to arbitrary file reads and writes (bsc#1275756). - CVE-2026-73621: argument injection in the `Commit.count()` method allows for destruction/blanking of arbitrary files (bsc#1275757). - CVE-2026-73622: failure to disable environment variable expansion in `Remote.create()` and `Submodule.add()` URL handling allows for secret exfiltration via URLs containing variable references (bsc#1275751). - CVE-2026-73623: incomplete denylist in `unsafe_git_clone_options` that omits `--template` allows for arbitrary command execution (bsc#1275752). - CVE-2026-73624: `Diffable.diff` method fails to validate git options passed through `kwargs`, which can lead to arbitrary file writes (bsc#1275753). - CVE-2026-73625: `check_unsafe_options` guard bypass via smuggling of git options inside single-character `kwarg` values can lead to arbitrary code execution (bsc#1275754). - CVE-2026-76217: failure to validate options passed to `git rm` and `git checkout` commands in `IndexFile.remove()` and `Head.checkout()` can lead to arbitrary file reads (bsc#1275745). - CVE-2026-76218: unguarded git option forwarding in `Repo.init` allows for arbitrary command execution (bsc#1275746). - CVE-2026-76219: unguarded `git read-tree` option forwarding in `IndexFile.from_tree/reset/merge_tree` can lead to arbitrary file overwrites (bsc#1275747). - CVE-2026-76220: `check_unsafe_options` guard can be bypassed by combining a single-character `kwarg` with `split_single_char_options=False`, which can lead to arbitrary OS command injection (bsc#1275748). - CVE-2026-76221: `config-name` injection in the `option-name` validator can lead to remote code execution (bsc#1275749). - CVE-2026-76222: failure to validate submodule names from `.gitmodules` files allows creation of Git repositories at arbitrary filesystem paths outside the intended clone directory (bsc#1275750). - CVE-2026-78675: fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives (bsc#1276434). - CVE-2026-78676: fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives (bsc#1276433). - CVE-2026-78677: allowing creation of arbitrary git directories outside the intended clone destination (bsc#1276432). - CVE-2026-78678: an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files (bsc#1276431). - CVE-2026-78679: an arbitrary file read vulnerability in TagReference.create() (bsc#1276430).

Affected Systems

  • susepython-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise Module for Python 3 15 SP7

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise Server 15 SP5-LTSS

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise Server 15 SP6-LTSS

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP5

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

  • susepython-GitPython&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP6

    < 3.1.34.1693646983.2a2ae77-150400.9.8.1

References (56)