← Back to CVE search

CVE-2026-42284

GitPython

Description

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(- -.join(multi_options)). A string like ---branch main --config core.hooksPath=/x- passes validation (starts with --branch), but after split becomes [---branch-, -main-, ---config-, -core.hooksPath=/x-]. Git applies the config and executes attacker hooks during clone. This issue has been patched in version 3.1.47.

CVSS 8.1EPSS 0.571%Risk 0.85
View source
Published
2026-05-07 19:16:01
Affected versions
<3.1.47
Type
Package
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H