THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wvpp-8hx9-p66j (high) — GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

[GHSA] GHSA-wvpp-8hx9-p66j (high) — GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

medgithub_advisoriesPublished 2026-08-07

GHSA-wvpp-8hx9-p66j Severity: high CVE: None

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

## Summary The `check_unsafe_options` guard can be bypassed on every guarded method (clone/clone_from, fetch/pull/push, ls_remote, iter_commits, blame, archive) by combining a single-character kwarg with `split_single_ch

Original source: https://github.com/advisories/GHSA-wvpp-8hx9-p66j