THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jm78-9fvv-mhgr (high) — GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

[GHSA] GHSA-jm78-9fvv-mhgr (high) — GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

medgithub_advisoriesPublished 2026-08-07

GHSA-jm78-9fvv-mhgr Severity: high CVE: None

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

## Summary GitPython's config-name validator only neutralizes CR/LF/NUL for the `"option"` label; it does not reject `=`, `#`, `;`, `[`, `]`, or whitespace in an **option name**. `write_section` writes the option name

Original source: https://github.com/advisories/GHSA-jm78-9fvv-mhgr