DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-59CR-6R3X-644W: GHSA-59CR-6R3X-644W: GitPython Submodule Update Path Traversal Can Write Outside the Repository

GHSA-59CR-6R3X-644W: GitPython Submodule Update Path Traversal Can Write Outside the Repository

Vulnerability ID: GHSA-59CR-6R3X-644W
CVSS Score: 8.8
Published: 2026-09-30

A path traversal vulnerability exists in GitPython when handling submodule updates recursively. If an attacker crafts a malicious repository with traversed paths or symbolic links in the submodule configuration, they can execute arbitrary file writes outside the parent repository's working directory. This can lead to system configuration modifications or arbitrary code execution.

TL;DR

GitPython versions up to 3.1.61 do not validate submodule update paths, allowing recursive checkouts to execute directory traversals and write files outside repository boundaries.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22, CWE-59
  • Attack Vector: Local/Remote via User Interaction
  • CVSS Score: 8.8
  • Impact: Arbitrary File Write / Code Execution
  • Exploit Status: Proof of Concept (PoC)
  • CISA KEV Status: Not Listed

Affected Systems

  • Applications utilizing GitPython for repository handling and submodule synchronization
  • Continuous Integration/Continuous Deployment (CI/CD) pipelines executing automated git checkout actions
  • GitPython: <= 3.1.61 (Fixed in: 3.1.62)

Code Analysis

Commit: 1ed0ebc

Ensure submodule paths are contained within the repository and do not resolve via symlinks

Exploit Details

Mitigation Strategies

  • Upgrade GitPython to version 3.1.62 or higher
  • Enforce isolation boundaries (sandboxes/containers) for execution
  • Disable recursive submodule cloning for untrusted inputs

Remediation Steps:

  1. Audit your application's requirements file or virtual environment and identify the GitPython version
  2. Run pip install --upgrade 'GitPython>=3.1.62' to apply the official security patch
  3. Ensure all CI/CD pipelines and automated cloning scripts are configured to use the patched version

References


Read the full report for GHSA-59CR-6R3X-644W on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)