gpp_maybe
Security update for python-gitpython
SUSE-SLE-Module-Python3-15-SP7-2026-4072
This update for python-GitPython fixes the following issues: - CVE-2026-42215: command injection via Git options bypass (bsc#1264604). - CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605). - CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository (bsc#1264606). - CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608). - CVE-2026-67322: vulnerable to environment-variable exfiltration in Repo.clone_from() (bsc#1273357). - CVE-2026-67323: fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote() (bsc#1273358). - CVE-2026-67325: contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature (bsc#1273359). - CVE-2026-67326: fails to validate newline characters in the section parameter of config_writer() (bsc#1273364). - CVE-2026-69097: fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names (bsc#1273414). - CVE-2026-73619: incomplete denylist in the `unsafe_git_archive_options` guard that omits `--add-file` and `--add- virtual-file` options can lead to arbitrary file reads (bsc#1275755). - CVE-2026-73620: failure to guard git option forwarding in `IndexFile.checkout()` and `TagReference.create()` can lead to arbitrary file reads and writes (bsc#1275756). - CVE-2026-73621: argument injection in the `Commit.count()` method allows for destruction/blanking of arbitrary files (bsc#1275757). - CVE-2026-73622: failure to disable environment variable expansion in `Remote.create()` and `Submodule.add()` URL handling allows for secret exfiltration via URLs containing variable references (bsc#1275751). - CVE-2026-73623: incomplete denylist in `unsafe_git_clone_options` that omits `--template` allows for arbitrary command execution (bsc#1275752). - CVE-2026-73624: `Diffable.diff` method fails to validate git options passed through `kwargs`, which can lead to arbitrary file writes (bsc#1275753). - CVE-2026-73625: `check_unsafe_options` guard bypass via smuggling of git options inside single-character `kwarg` values can lead to arbitrary code execution (bsc#1275754). - CVE-2026-76217: failure to validate options passed to `git rm` and `git checkout` commands in `IndexFile.remove()` and `Head.checkout()` can lead to arbitrary file reads (bsc#1275745). - CVE-2026-76218: unguarded git option forwarding in `Repo.init` allows for arbitrary command execution (bsc#1275746). - CVE-2026-76219: unguarded `git read-tree` option forwarding in `IndexFile.from_tree/reset/merge_tree` can lead to arbitrary file overwrites (bsc#1275747). - CVE-2026-76220: `check_unsafe_options` guard can be bypassed by combining a single-character `kwarg` with `split_single_char_options=False`, which can lead to arbitrary OS command injection (bsc#1275748). - CVE-2026-76221: `config-name` injection in the `option-name` validator can lead to remote code execution (bsc#1275749). - CVE-2026-76222: failure to validate submodule names from `.gitmodules` files allows creation of Git repositories at arbitrary filesystem paths outside the intended clone directory (bsc#1275750). - CVE-2026-78675: fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives (bsc#1276434). - CVE-2026-78676: fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives (bsc#1276433). - CVE-2026-78677: allowing creation of arbitrary git directories outside the intended clone destination (bsc#1276432). - CVE-2026-78678: an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files (bsc#1276431). - CVE-2026-78679: an arbitrary file read vulnerability in TagReference.create() (bsc#1276430).
-
Release DateSep 8 2026
-
ReferencesBugzilla: 1264604, 1264605, 1264606, 1264608, 1273357, 1273358, 1273359, 1273364, 1273414, 1273498, 1275745, 1275746, 1275747, 1275748, 1275749, 1275750, 1275751, 1275752, 1275753, 1275754, 1275755, 1275756, 1275757, 1276430, 1276431, 1276432, 1276433, 1276434
CVEs: CVE-2026-76218, CVE-2026-42215, CVE-2026-42284, CVE-2026-44243, CVE-2026-44244, CVE-2026-67322, CVE-2026-67323, CVE-2026-67325, CVE-2026-67326, CVE-2026-69097, CVE-2026-73619, CVE-2026-73620, CVE-2026-73621, CVE-2026-73622, CVE-2026-73623, CVE-2026-73624, CVE-2026-73625, CVE-2026-76217, CVE-2026-76219, CVE-2026-76220, CVE-2026-76221, CVE-2026-76222, CVE-2026-78675, CVE-2026-78676, CVE-2026-78677, CVE-2026-78678, CVE-2026-78679 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Python 3 Module 15.7 x86_64
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.8.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.8.1 lock rpm
Python 3 Module 15.7 aarch64
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.8.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.8.1 lock rpm
Python 3 Module 15.7 ppc64le
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.8.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.8.1 lock rpm
Python 3 Module 15.7 s390x
-
Packagespython-GitPython
Python Git Librarypython311-GitPython3.1.34.1693646983.2a2ae77-150400.9.8.1 lock src
Python Git Library3.1.34.1693646983.2a2ae77-150400.9.8.1 lock rpm