UNKNOWNPyPI

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.

CVE-2026-73622Published 4 weeks agoUpdated 5 days agoSource: OSV

Affected packages

  • gitpythonbefore 3.1.55

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl | HackTribune