THREAT OPS › Threat News › [NVD] CVE-2026-67325 (HIGH 8.8) — GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso
[NVD] CVE-2026-67325 (HIGH 8.8) — GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso
CVE-2026-67325 CVSS: 8.8 HIGH Published: 2026-08-01T13:17:02.923
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary comma
Indicators of compromise
- CVE-2026-67325cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67325