CVE-2023-40590: Untrusted search path on Windows systems leading to arbitrary code execution

Published Aug 28, 2023
·
Updated

Summary

When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment (see big warning in https://docs.python.org/3/library/subprocess.html#popen-constructor). GitPython defaults to use the git command, if a user runs GitPython from a repo has a git.exe or git executable, that program will be run instead of the one in the user's PATH.

Details

This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo.

The execution of the git command happens in

https://github.com/gitpython-developers/GitPython/blob/1c8310d7cae144f74a671cbe17e51f63a830adbf/git/cmd.py#L277

https://github.com/gitpython-developers/GitPython/blob/1c8310d7cae144f74a671cbe17e51f63a830adbf/git/cmd.py#L983-L996

And there are other commands executed that should probably be aware of this problem.

PoC

On a Windows system, create a git.exe or git executable in any directory, and import or run GitPython from that directory

python -c "import git"

The git executable from the current directory will be run.

Impact

An attacker can trick a user to download a repository with a malicious git executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands.

Possible solutions - Default to an absolute path for the git program on Windows, like C:\\Program Files\\Git\\cmd\\git.EXE (default git path installation). - Require users to set the GITPYTHONGITEXECUTABLE environment variable on Windows systems. - Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the GITPYTHONGITEXECUTABLE env var to an absolute path. - Resolve the executable manually by only looking into the PATH environment variable (suggested by @Byron)

---

[!NOTE] This vulnerability was reported via email, and it was decided to publish it here and make it public, so the community is aware of it, and a fix can be provided.

Other sources

GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the git command, if a user runs GitPython from a repo has a git.exe or git executable, that program will be run instead of the one in the user's PATH. This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo. An attacker can trick a user to download a repository with a malicious git executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands. There is no fix currently available for windows users, however there are a few mitigations. 1: Default to an absolute path for the git program on Windows, like C:\\Program Files\\Git\\cmd\\git.EXE (default git path installation). 2: Require users to set the GITPYTHONGITEXECUTABLE environment variable on Windows systems. 3: Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the GITPYTHONGITEXECUTABLE env var to an absolute path. 4: Resolve the executable manually by only looking into the PATH environment variable.

MITRE

Affected Software

2 affected componentsFixes available
pip/gitpython<=3.1.32
3.1.33
Gitpython Project Gitpython Python<=3.1.32

Event History

Aug 28, 2023
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 29, 2023
Advisory Published
11:33 PM

Frequently Asked Questions

1

What is the severity of CVE-2023-40590?

CVE-2023-40590 has been rated as a medium severity vulnerability.

2

How do I fix CVE-2023-40590?

To fix CVE-2023-40590, you should upgrade GitPython to version 3.1.33 or later.

3

Which versions of GitPython are affected by CVE-2023-40590?

GitPython versions up to and including 3.1.32 are affected by CVE-2023-40590.

4

What type of attack does CVE-2023-40590 facilitate?

CVE-2023-40590 can facilitate command injection attacks when using the GitPython library.

5

Is CVE-2023-40590 related to file handling in GitPython?

Yes, CVE-2023-40590 is related to how GitPython handles subprocess calls and working directories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203