CVE-2026-69097
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.
- Affected products
- Gitpython
- Fix
- Available
- CVSS 4.0
- 7.3 HIGH
- CVSS 3.1
- 7.0 HIGH
- EPSS
- 0.2% (9th percentile)
- Weakness
- CWE-74
- NVD status
- Received
- Published
- 2026-08-03
CVE-2026-69097 at NVD
No indexed exploits for CVE-2026-69097 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-69097 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.