HIGHVulnerability

CVE-2026-76222

GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped filesystem locations.

Properties

severity
HIGH
score
8.2
epss_score
0.00333
cve_id
CVE-2026-76222
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
published_at
2026-08-19T14:17:48.603
last_modified
2026-09-02T19:37:05.047
epss_percentile
0.26076

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76222 — Ninja Signal Threat Intelligence | Ninja Signal