Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100689— GitPython before 3.1.62 Path Traversal via gitmodules path

Quick assessment

Affected
gitpython-developers GitPython
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 GitPython 3.1.62 版本之前,当更新子模块时,程序未对从不信任的 文件中读取的 字段进行验证。此前的一项修复(GHSA-hmq2-w58f-27jc)引入了 以限制 字段,并且 GitPython 自身在 和 方法中应用了名为 的边界检查机制。然而,在 方法中,程序直接从原始的 值派生出绝对检出位置,而未应用该边界检查。因此,包含目录遍历组件(例如 )的 条目可能导致通过 在仓库工作树之外创建目录,并从克隆路径中的子模块 URL 填充这些目录;若使用 选项,还会通过 将其删除。 利用此漏洞需要应用

CVSS 5.9 · Medium EPSS 0.40% · P32

Affected Version Matrix 2

VendorProduct Version RangeStatus
gitpython-developers GitPython < 3.1.62 affected
3.1.62 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100689

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GitPython before 3.1.62 Path Traversal via gitmodules path
Source: CVE Program / CVE List V5
Vulnerability Description
GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPython's own containment guard Submodule._to_relative_path() is applied in add() and move(), Submodule.update() derives the absolute checkout location from the raw `path` value without that guard. A .gitmodules entry containing directory traversal components (e.g., path = ../../../tmp/escaped) can therefore cause directories to be created via os.makedirs() outside the repository working tree, populated from the submodule URL on the clone path, and removed via shutil.rmtree() when force_remove is used. Exploitation requires an application flow that updates submodules at a non-HEAD commit (such as a historical-commit API); the common clone-then-update flow re-derives the path from a canonical tree lookup and is not affected. The issue is fixed in GitPython 3.1.62.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
gitpython-developers GitPython 0 ~ 3.1.62 -

II. Public POCs for CVE-2026-100689

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100689

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100689 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100689

No comments yet


Leave a comment