THREAT OPS › Threat News › [GHSA] GHSA-284h-m62q-gf8w (critical) — GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
[GHSA] GHSA-284h-m62q-gf8w (critical) — GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
GHSA-284h-m62q-gf8w Severity: critical CVE: CVE-2026-78676
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
- **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument - **Affected component
Indicators of compromise
- 9729ed3b948f2bde09f1f188c5311e172212b67esha1
- CVE-2026-78676cve
Original source: https://github.com/advisories/GHSA-284h-m62q-gf8w