在 3.1.60 之前的 GitPython 未能正确验证 git 目录的位置,攻击者可以通过诸如 、 和 等受跟踪文件来冒充 git 目录。攻击者可以通过在受跟踪的 hooks 目录中放置一个恶意的 pre-commit 钩子,当受害者对克隆或打开的仓库调用 时,该钩子将被执行,从而执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gitpython-developers | GitPython | 0 ~ 3.1.60 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87819 | 7.5 HIGH | GitPython before 3.1.60 Denial of Service via ReDoS |
| CVE-2026-87818 | 6.5 MEDIUM | GitPython 3.1.59 Local File Content Oracle via --no-index |
No comments yet