


Perceptive Security
SOC/SIEM Consultancy

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers…
Published:
31 juli 2026 om 22:00:00
Alert date:
1 augustus 2026 om 14:10:40
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Zero-Day Vulnerabilities
GitPython versions before 3.1.50 contain a critical vulnerability in the config_writer() function that fails to validate newline characters in the section parameter. This allows attackers to inject arbitrary section headers into the .git/config file. By injecting newlines, an attacker can forge a [core] section with a hooksPath pointing to an attacker-controlled directory. When git hooks are subsequently triggered, this leads to remote code execution. The vulnerability is straightforward to exploit and affects any application using the GitPython library below version 3.1.50. Users are advised to upgrade to GitPython 3.1.50 or later to remediate the issue. The vulnerability has been assigned CVE-2026-67326 and is documented in both the NVD and GitHub Security Advisories.
Technical details
Mitigation steps:
Affected products:
GitPython before 3.1.50
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67326
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w
https://www.vulncheck.com/advisories/gitpython-before-newline-injection-via-config-writer-section
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
