HIGHVulnerability
CVE-2026-76222
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.
Properties
- severity
- HIGH
- score
- 8.2
- epss_score
- 0.00333
- cve_id
- CVE-2026-76222
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
- published_at
- 2026-08-19T14:17:48.603
- last_modified
- 2026-09-02T19:37:05.047
- epss_percentile
- 0.26076
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
AFFECTS_PRODUCT (1)
→[Product]
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Explore deeper with Ninja Signal's threat intelligence graph