{"id":"SUSE-SU-2026:4072-1","summary":"Security update for python-GitPython","details":"This update for python-GitPython fixes the following issues:\n\n- CVE-2026-42215: command injection via Git options bypass (bsc#1264604).\n- CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605).\n- CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the\n  repository (bsc#1264606).\n- CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608).\n- CVE-2026-67322: vulnerable to environment-variable exfiltration in Repo.clone_from() (bsc#1273357).\n- CVE-2026-67323: fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and\n  git.ls_remote() (bsc#1273358).\n- CVE-2026-67325: contains an incomplete command injection blocklist that fails to account for git's long-option prefix\n  abbreviation feature (bsc#1273359).\n- CVE-2026-67326: fails to validate newline characters in the section parameter of config_writer() (bsc#1273364).\n- CVE-2026-69097: fails to properly escape section names in git config files, allowing attackers to inject arbitrary\n  configuration directives through malicious submodule names (bsc#1273414).\n- CVE-2026-73619: incomplete denylist in the `unsafe_git_archive_options` guard that omits `--add-file` and `--add-\n  virtual-file` options can lead to arbitrary file reads (bsc#1275755).\n- CVE-2026-73620: failure to guard git option forwarding in `IndexFile.checkout()` and `TagReference.create()` can lead\n  to arbitrary file reads and writes (bsc#1275756).\n- CVE-2026-73621: argument injection in the `Commit.count()` method allows for destruction/blanking of arbitrary files\n  (bsc#1275757).\n- CVE-2026-73622: failure to disable environment variable expansion in `Remote.create()` and `Submodule.add()` URL\n  handling allows for secret exfiltration via URLs containing variable references (bsc#1275751).\n- CVE-2026-73623: incomplete denylist in `unsafe_git_clone_options` that omits `--template` allows for arbitrary command\n  execution (bsc#1275752).\n- CVE-2026-73624: `Diffable.diff` method fails to validate git options passed through `kwargs`, which can lead to\n  arbitrary file writes (bsc#1275753).\n- CVE-2026-73625: `check_unsafe_options` guard bypass via smuggling of git options inside single-character `kwarg`\n  values can lead to arbitrary code execution (bsc#1275754).\n- CVE-2026-76217: failure to validate options passed to `git rm` and `git checkout` commands in `IndexFile.remove()` and\n  `Head.checkout()` can lead to arbitrary file reads (bsc#1275745).\n- CVE-2026-76218: unguarded git option forwarding in `Repo.init` allows for arbitrary command execution (bsc#1275746).\n- CVE-2026-76219: unguarded `git read-tree` option forwarding in `IndexFile.from_tree/reset/merge_tree` can lead to\n  arbitrary file overwrites (bsc#1275747).\n- CVE-2026-76220: `check_unsafe_options` guard can be bypassed by combining a single-character `kwarg` with\n  `split_single_char_options=False`, which can lead to arbitrary OS command injection (bsc#1275748).\n- CVE-2026-76221: `config-name` injection in the `option-name` validator can lead to remote code execution\n  (bsc#1275749).\n- CVE-2026-76222: failure to validate submodule names from `.gitmodules` files allows creation of Git repositories at\n  arbitrary filesystem paths outside the intended clone directory (bsc#1275750).\n- CVE-2026-78675: fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file\n  content by including arbitrary file paths via [include] directives (bsc#1276434).\n- CVE-2026-78676: fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant\n  quoted values into injected directives (bsc#1276433).\n- CVE-2026-78677: allowing creation of arbitrary git directories outside the intended clone destination (bsc#1276432).\n- CVE-2026-78678: an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options,\n  allowing attackers to read arbitrary files (bsc#1276431).\n- CVE-2026-78679: an arbitrary file read vulnerability in TagReference.create() (bsc#1276430).\n","modified":"2026-09-13T18:23:37.314577005Z","published":"2026-09-08T07:07:35Z","related":["CVE-2026-42215","CVE-2026-42284","CVE-2026-44243","CVE-2026-44244","CVE-2026-67322","CVE-2026-67323","CVE-2026-67325","CVE-2026-67326","CVE-2026-69097","CVE-2026-73619","CVE-2026-73620","CVE-2026-73621","CVE-2026-73622","CVE-2026-73623","CVE-2026-73624","CVE-2026-73625","CVE-2026-76217","CVE-2026-76218","CVE-2026-76219","CVE-2026-76220","CVE-2026-76221","CVE-2026-76222","CVE-2026-78675","CVE-2026-78676","CVE-2026-78677","CVE-2026-78678","CVE-2026-78679"],"upstream":["CVE-2026-42215","CVE-2026-42284","CVE-2026-44243","CVE-2026-44244","CVE-2026-67322","CVE-2026-67323","CVE-2026-67325","CVE-2026-67326","CVE-2026-69097","CVE-2026-73619","CVE-2026-73620","CVE-2026-73621","CVE-2026-73622","CVE-2026-73623","CVE-2026-73624","CVE-2026-73625","CVE-2026-76217","CVE-2026-76218","CVE-2026-76219","CVE-2026-76220","CVE-2026-76221","CVE-2026-76222","CVE-2026-78675","CVE-2026-78676","CVE-2026-78677","CVE-2026-78678","CVE-2026-78679"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264072-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264604"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264605"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264608"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273357"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273358"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273359"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273364"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273414"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273498"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275745"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275746"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275747"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275748"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275749"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275750"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275751"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275753"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275754"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275755"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275756"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275757"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276431"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276432"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276433"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276434"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42284"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44244"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67322"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67323"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67326"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-69097"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73621"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73623"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73624"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73625"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76218"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76220"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76221"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76222"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78679"}],"affected":[{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise Module for Python 3 15 SP7","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}},{"package":{"name":"python-GitPython","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/python-GitPython&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]}],"ecosystem_specific":{"binaries":[{"python311-GitPython":"3.1.34.1693646983.2a2ae77-150400.9.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4072-1.json"}}],"schema_version":"1.9.0"}