GHSA-9rj7-rf2p-w77r: Code Injection
Summary Repo.init() forwards kwargs verbatim to git init with no unsafe-option guard and no allowunsafeoptions parameter. git init --template=<dir> copies <dir>/hooks/ into the new repo's .git/hooks, so an attacker-controlled template kwarg plants a hook that executes on the next git operation → arbitrary code execution. --template is already recognized as unsafe for clone (it is on unsafegitcloneoptions, and GHSA-6p8h-3wgx-97gf covers the clone path), but Repo.init is a distinct method that never received a guard and needs an independent fix.
Root Cause Repo.init(path, mkdir, odbt, expandvars, kwargs) is a bare git.init(kwargs) (git/repo/base.py:1435) with no checkunsafeoptions and no allowunsafeoptions.
Impact Arbitrary code execution (hook fires on next git op) at the privileges of the host process. Two preconditions raise attack complexity (AC:H): the app must forward a template= kwarg (KEY control) AND the attacker must stage an executable hook directory at a known path — the same profile GHSA-6p8h-3wgx-97gf accepted as HIGH for the clone path. Default allowunsafeoptions is irrelevant here because Repo.init has no guard at all.
Proof of Concept python attacker stages /evil/hooks/post-commit (executable) from git import Repo Repo.init(path, template="/evil") next commit runs /evil/hooks/post-commit -> ACE
Attack Chain 1. Entry: attacker stages /evil/hooks/post-commit (executable) and gets the app to call Repo.init(path, template='/evil'). 2. Check: NONE on Repo.init. Bypass proof: base.py:1435 is a bare git.init(kwargs). argv (observed): ['git','init','--template=/evil']. 3. Sink: git copies /evil/hooks/post-commit → <repo>/.git/hooks/post-commit. 4. Impact: next commit runs the hook → arbitrary code execution.
Bypass Evidence Independently reproduced (gate harness): Repo.init(dst, template='<evil>') → argv ['git','init','--template=<evil>'] unguarded; hook copied into .git/hooks/post-commit; after git commit the INITACE marker was created. --separate-git-dir=<path> is a parallel arbitrary-redirect vector through the same unguarded sink (value control only).
Affected Versions GitPython <= 3.1.57 (unguarded git.init(kwargs) present verbatim on the latest release tag).
Suggested Fix Add a checkunsafeoptions guard (with an allowunsafeoptions parameter) to Repo.init, consulting a denylist that includes --template and --separate-git-dir (path-taking / hook-installing options).
--- Reported by zx (Jace) — GitHub: @manus-use
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/GitPythonto a version that resolves this vulnerability.Fixed in 3.1.58 - Configuration
In Repo.init, add a check_unsafe_options guard (with an allow_unsafe_options parameter) that consults a denylist including --template and --separate-git-dir, and blocks forwarding these unsafe options to the underlying `git init` call (git/repo/base.py:1435 uses a bare `git.init(**kwargs)`).
GitPython Repo.init allow_unsafe_options / check_unsafe_options guard for git init kwargs = denylist includes --template and --separate-git-dir - Compensating control
Ensure the application does not forward attacker-controlled `template=` (or other unsafe git init redirect/hook-installing options such as `--separate-git-dir`) into `Repo.init`, since `git init --template=<dir>` copies `<dir>/hooks/*` into `<repo>/.git/hooks` and triggers arbitrary code execution on the next git operation.
Event History
Frequently Asked Questions
What is the severity of GHSA-9rj7-rf2p-w77r?
The severity of GHSA-9rj7-rf2p-w77r is classified as high with a CVSS score of 7.5.
How do I fix GHSA-9rj7-rf2p-w77r?
To fix GHSA-9rj7-rf2p-w77r, ensure that you are not using the vulnerable `git init` methods without proper restriction of unsafe options and update to the latest version of GitPython.
What are the potential impacts of GHSA-9rj7-rf2p-w77r?
The potential impacts of GHSA-9rj7-rf2p-w77r include code injection, allowing unauthorized execution of commands through malicious git hooks.
Which software versions are affected by GHSA-9rj7-rf2p-w77r?
GHSA-9rj7-rf2p-w77r affects the GitPython library, particularly versions that allow unsafe options in `Repo.init()`.
Is GHSA-9rj7-rf2p-w77r a persistent vulnerability?
Yes, GHSA-9rj7-rf2p-w77r can lead to persistent vulnerabilities if an attacker can exploit the repository with malicious template arguments.