Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution. | |
| Title | GitPython before 3.1.59 Path Traversal via separate-git-dir | |
| First Time appeared |
Gitpython Project
Gitpython Project gitpython |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitpython Project
Gitpython Project gitpython |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T01:30:34.719Z
Reserved: 2026-08-25T01:17:12.262Z
Link: CVE-2026-78677
No data.
Status : Received
Published: 2026-08-25T02:16:52.173
Modified: 2026-08-25T02:16:52.173
Link: CVE-2026-78677
No data.
OpenCVE Enrichment
Updated: 2026-08-25T04:15:04Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')