Executive brief
GitPython is a Python library used by developers to interact with Git repositories programmatically. A flaw in its clone functionality allows attackers to execute arbitrary commands on systems that use GitPython to clone untrusted repositories. An attacker can exploit this by providing a specially crafted --template parameter pointing to a directory with malicious Git hooks that execute during the clone process, potentially compromising the integrity of systems relying on this library.
Technical details
GitPython versions before 3.1.54 fail to properly validate the --template parameter in the unsafe_git_clone_options denylist within base.py (lines 145-152). The --template option in git clone copies hook files from a specified directory into the new repository and executes them (specifically the post-checkout hook) during checkout. An attacker with control over clone parameters can bypass the incomplete denylist by supplying --template pointing to an attacker-controlled or world-writable directory containing a malicious post-checkout hook. The vulnerability requires an attacker-readable directory with executable hooks, a realistic precondition on shared filesystems, upload directories, /tmp, or network paths. The fix involves adding --template to the unsafe_git_clone_options denylist and auditing for other hook/exec-influencing options. Patched in version 3.1.54.
Affected products
- GitPython GitPython before 3.1.54
Timeline
- 2026-07-22: disclosed: GitHub Security Advisory GHSA-6p8h-3wgx-97gf published
- 2026-08-13: advisory: CVE-2026-73623 published on NVD
- 2026: patched: Fixed in GitPython 3.1.54