LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-69097

Published
CVSS7
Severityhigh
WeaknessCWE-74
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-69097

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-69097.