REDHAT-BUG-2509975: Command Injection
Published Aug 1, 2026
·Updated
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like uploadp instead of uploadpack, which git resolves to dangerous options and executes arbitrary commands.
Affected Software
1 affected component
GitPython GitPython<3.1.51
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitPythonto a version that resolves this vulnerability.Fixed in 3.1.51
Event History
Aug 1, 2026
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software