Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository. | |
| Title | GitPython before 3.1.58 Remote Code Execution via Repo.init | |
| First Time appeared |
Gitpython Project
Gitpython Project gitpython |
|
| Weaknesses | CWE-88 | |
| CPEs | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitpython Project
Gitpython Project gitpython |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-19T15:02:13.151Z
Reserved: 2026-08-19T11:35:13.689Z
Link: CVE-2026-76218
No data.
Status : Received
Published: 2026-08-19T14:17:48.040
Modified: 2026-08-19T15:18:10.590
Link: CVE-2026-76218
No data.
OpenCVE Enrichment
No data.
-
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')