CVE-2026-78677Active Exploitation(gitpython_project / gitpython)

LOWCVSS 8.7 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for gitpython_project gitpython systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitpython

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
gitpython

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 2Active Exploitation · 2026-08-25: 1Technical Details · 2026-08-25: 208-25
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • NewNormal Security@NewScanTeam
    Active Exploitation

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 25 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 📦 Outdated IT service management platform — unauthenticated file deletion reaching code execution (Combodo iTop CVE-2026-39975, CVE-2026-30864, CVE-2026-40877) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🚨 Actively-exploited Oracle web tier — unauthenticated read of critical data straight off the internet-facing front door (Oracle CVE-2026-21962) 📦 Outdated web database console — unauthenticated code execution on the host running it, no login needed (Adminer CVE-2026-56705, CVE-2026-56703, CVE-2026-34968, CVE-2026-56702, CVE-2026-56706, CVE-2026-56704, CVE-2026-34967, CVE-2026-34964, CVE-2026-34959) 📦 Vulnerable Git library pinned in a served manifest — attacker-chosen code runs on the next git command (GitPython CVE-2026-78676, CVE-2026-78677, CVE-2026-78678) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #RCE #CSO #REDTEAM

    Post summary

    The report announces that several CVEs, notably Oracle CVE‑2026‑21962, are currently being exploited in the wild, providing technical details but lacking information on PoCs or patches.

    0100072
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78677 GitPython Directory Traversal and Hook Execution Vulnerability Be... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78677 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑78677 as a GitPython directory traversal and hook execution vulnerability, linking to a Vulmon details page for further information.

    00000118
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitpython_projectgitpython-python-

Explore more