CVE-2026-69097
Description
A flaw was found in GitPython. This vulnerability allows an attacker to inject malicious configuration directives into Git configuration files by using specially crafted submodule names. This can lead to remote code execution, enabling the attacker to run unauthorized commands on the affected system when Git performs SSH operations.
Statement
Moderate: This flaw in GitPython allows for remote code execution within Red Hat products that utilize GitPython to process Git repositories. An attacker could inject arbitrary Git configuration directives, such as core.sshCommand, by crafting malicious submodule names. This occurs when a user performs create_submodule or clone_from operations on an untrusted repository, leading to code execution during subsequent Git SSH operations.
Mitigation
To mitigate this issue, users should avoid cloning or creating submodules from untrusted Git repositories. Exercise caution when interacting with Git repositories from unknown or unverified sources, as processing malicious submodule names can lead to configuration injection and potential remote code execution. Always ensure the integrity and trustworthiness of Git repositories before performing operations that involve submodule creation or cloning.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7 | 7.3 | 7 |
| Attack Vector | Local | Local | Local |
| Attack Complexity | High | Low | High |
| Privileges Required | None | Low | None |
| User Interaction | Required | Required | Required |
| Scope | Unchanged | Unchanged | Unchanged |
| Confidentiality | High | High | High |
| Integrity Impact | High | High | High |
| Availability Impact | High | High | High |
Vector
Red Hat: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability,Non-Repudiation
Technical Impact: Execute Unauthorized Code or Commands; DoS: Crash, Exit, or Restart; Read Files or Directories; Modify Files or Directories; Read Application Data; Modify Application Data; Hide Activities
Attackers could execute unauthorized operating system commands, which could then be used to disable the product, or read and modify data for which the attacker does not have permissions to access directly. Since the targeted application is directly executing the commands instead of the attacker, any malicious activities may appear to come from the application or the application's owner.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.