CVE-2026-78676Disclosure(gitpython_project / gitpython)

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch gitpython_project gitpython systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitpython

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
gitpython

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-25: 3Mentions · 2026-09-16: 1Active Exploitation · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 208-2509-16
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-253
Active Exploitation1Disclosure1General1
2026-09-161
Disclosure1
Full discourse4 posts
  • Ryx@PadhiyarRushi
    Disclosure

    OX Research flagged four critical CVEs in a 24-hour window that all share the same root issue: a component trusting the layer next to it. Netty (CVE-2026-75595), Next.js (CVE-2026-75604), a GHSA in the same class, and GitPython (CVE-2026-78676). When the trust boundary between adjacent components is assumed rather than enforced, these land hard and fast. https://www.ox.security/blog/four-critical-cves-the-same-trust-issue/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #SupplyChain

    Post summary

    The text announces four critical CVEs sharing a common trust boundary vulnerability issue, referencing a research blog post, but does not include PoC, exploit tools, patch information, or exploitation status.

    11043409
    954 followersView on X
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 25 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 📦 Outdated IT service management platform — unauthenticated file deletion reaching code execution (Combodo iTop CVE-2026-39975, CVE-2026-30864, CVE-2026-40877) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🚨 Actively-exploited Oracle web tier — unauthenticated read of critical data straight off the internet-facing front door (Oracle CVE-2026-21962) 📦 Outdated web database console — unauthenticated code execution on the host running it, no login needed (Adminer CVE-2026-56705, CVE-2026-56703, CVE-2026-34968, CVE-2026-56702, CVE-2026-56706, CVE-2026-56704, CVE-2026-34967, CVE-2026-34964, CVE-2026-34959) 📦 Vulnerable Git library pinned in a served manifest — attacker-chosen code runs on the next git command (GitPython CVE-2026-78676, CVE-2026-78677, CVE-2026-78678) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The report lists new CVEs, noting an actively exploited Oracle vulnerability while providing technical details but no PoC, exploit code, or patch information.

    0100072
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-78676 GitPython 3.1.59 Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78676 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet links to a vulnerability entry for CVE-2026-78676 affecting GitPython versions prior to 3.1.59, but it provides no technical details, exploit info, or patch information.

    0000099
    4.1K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 GitPython Mass Disclosure — 5 CVEs, CVSS 9.8 PEAK CVE-2026-78676 (9.8): Git-config injection → core.hooksPath RCE Update GitPython to 3.1.59+ NOW. Audit .git/config. → https://threataft.com/articles/gitpython-mass-disclosure-5-cves #cybersecurity #infosec #GitPython #Python #CICD #SupplyChain #RCE #ThreatIntel

    Post summary

    The post announces a mass disclosure of five GitPython CVEs, highlights a high‑severity Git-config injection leading to core.hooksPath RCE, and urges users to update to v3.1.59+ and audit their .git/config.

    0000047
    37 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitpython_projectgitpython-python-

Explore more