PT-2026-38295 · Pypi+2 · Gitpython+2

·

CVE-2026-44244

·

Published

2026-05-06

·

Updated

2026-07-10

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitPython versions prior to 3.1.49
Description The set value() function in GitConfigParser passes values to Python's configparser without validating for newlines. Although the write() function converts embedded newlines into indented continuation lines, Git still accepts an indented [core] stanza as a section header. This allows an attacker to inject a core.hooksPath configuration, redirecting Git hook execution (such as commit, merge, or checkout) to a path controlled by the attacker. This results in persistent repository configuration poisoning, where scripts can be executed in the context of any user performing Git operations on the affected repository.
Recommendations Update to version 3.1.49. As a temporary workaround, restrict or sanitize any external input passed to the set value() function to ensure it does not contain carriage returns (CR), line feeds (LF), or NUL characters.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44244
ECHO-75D1-905C-5401
GHSA-V87R-6Q3F-2J67
OESA-2026-2306
OESA-2026-2307
OESA-2026-2308
OPENSUSE-SU-2026:10758-1
OPENSUSE-SU-2026:20777-1
PYSEC-2026-2163
SUSE-SU-2026:21813-1
USN-8303-1

Affected Products

Gitpython
Linuxmint
Ubuntu