Executive brief
GitPython is a Python library used to interact with Git repositories. A vulnerability exists where an attacker can execute arbitrary commands on a system if they can influence the options passed to a repository clone operation. This could lead to full system compromise, unauthorized data access, or service disruption.
Technical details
A command injection vulnerability exists in GitPython due to an incomplete denylist in the `unsafe_git_clone_options` variable within `base.py`. The `--template` option is not restricted, allowing an attacker to specify a directory containing malicious Git hooks (e.g., `post-checkout`). When `Repo.clone_from()` is called with this option, Git copies the hooks into the new repository and executes them during the clone process. Exploitation requires the attacker to have a way to stage an executable hook in a directory readable by the process. This bypasses the default `allow_unsafe_options=False` protection. The issue is patched in version 3.1.54.
Affected products
- gitpython-developers GitPython <= 3.1.53
Timeline
- 2026-07-22: disclosed
- 2026-07-24: advisory: GHSA-6p8h-3wgx-97gf published
- 2026-07-24: patched: Version 3.1.54 released