THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-284h-m62q-gf8w (critical) — GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

[GHSA] GHSA-284h-m62q-gf8w (critical) — GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

highgithub_advisoriesPublished 2026-09-08

GHSA-284h-m62q-gf8w Severity: critical CVE: CVE-2026-78676

GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument - **Affected component

Indicators of compromise

Original source: https://github.com/advisories/GHSA-284h-m62q-gf8w