CVE-2026-78675

Name
CVE-2026-78675
Description
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-7833-fr7j-v32q
disclosure@vulncheck.com https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:* py3-gitpython >= None < 3.1.59

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-gitpython edge-community 3.1.61-r0 Wen Heping <wenhepingalpine@sohu.com> fixed
py3-gitpython edge-community 3.1.57-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.49-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.46-r1 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.46-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable
py3-gitpython edge-community 3.1.44-r0 None possibly vulnerable
py3-gitpython edge-community 3.1.43-r1 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
py3-gitpython edge-community 3.1.37-r0 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
py3-gitpython edge-community 3.1.35-r0 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
py3-gitpython 3.24-community 3.1.49-r0 Wen Heping <wenhepingalpine@sohu.com> possibly vulnerable