CVE-2026-76218: GitPython before 3.1.58 Remote Code Execution via Repo.init
Published Aug 19, 2026
·Updated
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
Affected Software
2 affected components
GitPython<3.1.58
Gitpython Project Gitpython Python<3.1.58
Event History
Aug 19, 2026
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of attacker access and interaction does the CVSS assessment indicate?
The assessment indicates network reachability, low privileges, and no user interaction are required. It also rates attack complexity as high.