
🚨HIGH - GitPython RCE via check_unsafe_options Bypass (CVE-2026-76220) GitPython’s option filtering in check_unsafe_options can be bypassed by using a single-character kwarg with split_single_char_options=False, causing joined tokens to be re-parsed as unsafe long options like --upload-pack. Passing a crafted kwargs dict into clone_from (and similar wrappers) can trigger arbitrary OS command execution even when allow_unsafe_options remains False. 👉Affected: GitPython < 3.1.58 | Upgrade to 3.1.58
Post summary
The post announces a high‑severity RCE in GitPython via check_unsafe_options bypass, providing technical details and recommending an upgrade to 3.1.58 to remediate.
