THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67325 (HIGH 8.8) — GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso

[NVD] CVE-2026-67325 (HIGH 8.8) — GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso

mednvdPublished 2026-08-01

CVE-2026-67325 CVSS: 8.8 HIGH Published: 2026-08-01T13:17:02.923

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary comma

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67325