


Perceptive Security
SOC/SIEM Consultancy

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers ca…
Published:
31 July 2026 at 22:00:00
Alert date:
1 August 2026 at 14:10:41
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Zero-Day Vulnerabilities
GitPython versions before 3.1.51 contain a vulnerability in their command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by supplying abbreviated option names such as 'upload_p' instead of 'upload_pack', which git internally resolves to the full dangerous option and executes arbitrary commands. This represents an incomplete fix or oversight in the security controls designed to prevent unsafe git option injection. The vulnerability allows remote or local attackers who can influence git command arguments to execute arbitrary commands on the system. Users and organizations relying on GitPython for git operations in automated pipelines, CI/CD systems, or web applications are at risk. The fix is available in GitPython 3.1.51, and users are strongly advised to upgrade immediately. The issue has been documented by both the GitPython developers via a GitHub Security Advisory and independently by VulnCheck.
Technical details
Mitigation steps:
Affected products:
GitPython
GitPython before 3.1.51
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67325
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx
https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
