CRITICALPyPI

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

CVE-2026-67326Published 2 months agoUpdated 3 days agoSource: OSV

Affected packages

  • gitpythonbefore 3.1.50

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.19%
EPSS percentile
9.0%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 9%.

GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath | HackTribune