THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hmq2-w58f-27jc (high) — GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

[GHSA] GHSA-hmq2-w58f-27jc (high) — GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

medgithub_advisoriesPublished 2026-08-07

GHSA-hmq2-w58f-27jc Severity: high CVE: None

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

### Summary GitPython computes the on-disk location of a submodule's separate Git directory (`.git/modules/<name>`) from the submodule's `.gitmodules` section name with no validation. Because that name is fully attacker-control

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hmq2-w58f-27jc