CRITICALPyPI

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

CVE-2026-69097Published 1 week agoUpdated 1 day agoSource: OSV

Affected packages

  • gitpythonbefore 3.1.53

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.19%
EPSS percentile
8.6%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 9%.

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE) | HackTribune