目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-100689— GitPython 3.1.62 前路径遍历漏洞

一分钟漏洞结论

影响对象
gitpython-developers GitPython
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 GitPython 3.1.62 版本之前,当更新子模块时,程序未对从不信任的 文件中读取的 字段进行验证。此前的一项修复(GHSA-hmq2-w58f-27jc)引入了 以限制 字段,并且 GitPython 自身在 和 方法中应用了名为 的边界检查机制。然而,在 方法中,程序直接从原始的 值派生出绝对检出位置,而未应用该边界检查。因此,包含目录遍历组件(例如 )的 条目可能导致通过 在仓库工作树之外创建目录,并从克隆路径中的子模块 URL 填充这些目录;若使用 选项,还会通过 将其删除。 利用此漏洞需要应用

CVSS 5.9 · Medium EPSS 0.40% · P32

影响版本矩阵 2

厂商产品 版本范围状态
gitpython-developers GitPython < 3.1.62 affected
3.1.62 unaffected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-100689 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
GitPython before 3.1.62 Path Traversal via gitmodules path
来源: CVE Program / CVE List V5
Vulnerability Description
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPython's own containment guard Submodule._to_relative_path() is applied in add() and move(), Submodule.update() derives the absolute checkout location from the raw `path` value without that guard. A .gitmodules entry containing directory traversal components (e.g., path = ../../../tmp/escaped) can therefore cause directories to be created via os.makedirs() outside the repository working tree, populated from the submodule URL on the clone path, and removed via shutil.rmtree() when force_remove is used. Exploitation requires an application flow that updates submodules at a non-HEAD commit (such as a historical-commit API); the common clone-then-update flow re-derives the path from a canonical tree lookup and is not affected. The issue is fixed in GitPython 3.1.62.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
gitpython-developers GitPython 0 ~ 3.1.62 -

二、漏洞 CVE-2026-100689 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-100689 的情报信息

请登录查看更多情报信息。

CVE-2026-100689 厂商安全公告 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100689

暂无评论


发表评论