GHSA-jm78-9fvv-mhgr: High severity pip/GitPython vulnerability
Summary GitPython's config-name validator only neutralizes CR/LF/NUL for the "option" label; it does not reject =, #, ;, [, ], or whitespace in an option name. writesection writes the option name verbatim into the config file, so an option name such as sshCommand = touch <cmd> # is written as \tsshCommand = touch <cmd> # = <value>, which git parses as core.sshCommand = touch <cmd> (the trailing # comments out the intended value). This forges arbitrary config directives (core.sshCommand, core.hooksPath, alias.) → RCE on the next git operation. This is a distinct field (option name, not section name) and distinct character class (=/#/space, not newline/bracket) from GHSA-3rp5-jjmw-4wv2 (section-name bracket injection) and GHSA-mv93-w799-cj2w / GHSA-v87r-6q3f-2j67 (newline injection).
Root Cause assureconfignamesafe(name, label) (git/config.py:897) applies the bracket/quote state machine ONLY when label == "section"; for the "option" label it falls through with just the UNSAFECONFIGCHARSRE = [\r\n\x00] regex. writesection then writes the option name verbatim into "\t%s = %s\n" (config.py:702).
Impact Arbitrary git-config directive injection → remote code execution via core.sshCommand (fires on any ssh git operation, no staged file needed) or core.hooksPath (with a staged hook). Requires the embedding application to forward a caller-influenced OPTION NAME into the config writer (name-control model, the same name-control model accepted by the related published advisories GHSA-3rp5-jjmw-4wv2 and GHSA-mv93-w799-cj2w). Default configuration.
Proof of Concept python with repo.configwriter() as cw: cw.setvalue("core", "sshCommand = touch /tmp/RCE #", "x") git config --get core.sshCommand -> touch /tmp/RCE
Attack Chain 1. Entry: app calls config writer with attacker-controlled OPTION name: setvalue("core", "sshCommand = touch /tmp/RCE #", "x"). 2. Check: assureconfignamesafe(option, "option") @ config.py. Guard: regex matches only [\r\n\x00]; bracket/quote state machine is gated on label=="section". Bypass proof: =,#,space pass → no ValueError. 3. Sink: writesection writes "\tsshCommand = touch /tmp/RCE # = x\n" (config.py:702). 4. Impact: git parses core.sshCommand=touch /tmp/RCE → arbitrary code execution on next git op.
Bypass Evidence Independently reproduced (gate harness): setvalue('core','sshCommand = touch <RCE> #','x') → no ValueError; file line sshCommand = touch <RCE> # = x; git config --get core.sshCommand → touch <RCE> (rc=0). Also verified core.hooksPath via both GitConfigParser and repo.configwriter(). Fix-commit read: bracket/quote checks are inside if label == "section"; the "option" label is not covered.
Affected Versions GitPython <= 3.1.57 (validator present verbatim on the latest release tag).
Suggested Fix Apply the section-name safety checks (reject =, #, ;, [, ], whitespace) to the "option" label as well, or validate the fully-rendered config line after substitution.
--- Reported by zx (Jace) — GitHub: @manus-use
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/GitPythonto a version that resolves this vulnerability.Fixed in 3.1.58 - Configuration
Update GitPython’s config writer validation so that `_assure_config_name_safe(..., "option")` applies the same safety checks described for section names (reject `=`, `#`, `;`, `[`, `]`, and whitespace) to the option name as well, or alternatively validates the fully-rendered config line after substitution to prevent directive injection into lines written by `write_section`.
GitPython (config.py) config name validation _assure_config_name_safe(name, label) safety checks = Apply section-name safety checks (reject `=`, `#`, `;`, `[`, `]`, whitespace) to the "option" label as well, or validate the fully-rendered config line after substitution.
Event History
Frequently Asked Questions
What is the severity of GHSA-jm78-9fvv-mhgr?
The severity of GHSA-jm78-9fvv-mhgr is high, with a CVSS score of 8.8.
How do I fix GHSA-jm78-9fvv-mhgr?
To fix GHSA-jm78-9fvv-mhgr, update GitPython to the latest version where this vulnerability has been addressed.
What is the risk associated with GHSA-jm78-9fvv-mhgr?
GHSA-jm78-9fvv-mhgr presents a risk level of 79, indicating a high potential for exploitation.
What types of input are not sanitized in GHSA-jm78-9fvv-mhgr?
GHSA-jm78-9fvv-mhgr does not sanitize input characters such as '=', '#', ';', '[', ']', or whitespace in option names.
Which software is affected by GHSA-jm78-9fvv-mhgr?
GHSA-jm78-9fvv-mhgr affects the GitPython library used in Python packages installed via pip.