CVE-2026-87817
Awaiting Analysis Awaiting Analysis - Queue

GitPython Directory Traversal and Code Execution Vulnerability

Vulnerability report for CVE-2026-87817, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gitpython_developers gitpython to 3.1.60 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GitPython before 3.1.60 fails to properly validate the git directory location. Attackers can impersonate the git directory using tracked files like gitdir, commondir, and HEAD. This allows them to place a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.

Detection Guidance

Check GitPython version with pip show GitPython. If version is below 3.1.60, the system is vulnerable. Inspect repositories for tracked files named gitdir, commondir, or HEAD in the root directory. Review pre-commit hooks in .git/hooks for suspicious scripts.

Impact Analysis

If you use GitPython versions before 3.1.60, an attacker could execute arbitrary code on your system by tricking you into working with a malicious repository. This could lead to data theft, system compromise, or further attacks within your environment.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations processing untrusted repositories may face compliance violations if exploited.

Mitigation Strategies

Upgrade GitPython to version 3.1.60 or later using pip install --upgrade GitPython. Avoid processing untrusted repositories in CI runners or dependency bots until upgraded. Remove any suspicious tracked files like gitdir, commondir, or HEAD from repositories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87817. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart