mediumVulnerability

GHSA-59cr-6r3x-644w

**Affected:** `GitPython` **3.1.61** (latest release) and `main` — `git/objects/submodule/base.py`. `git diff 3.1.61 origin/main -- git/objects/submodule/` is empty, so both are identical here. --- ## The gap The fix for `GHSA-hmq2-w58f-27jc` added `Submodule._validated_name()` and wired it into `update()` and five siblings, closing the `.gitmodules` **name** → `.git/modules/<name>` traversal. The other attacker-controlled `.gitmodules` field, **`path`**, is read raw: ```python # git/objects/submodule/base.py:172-177 def _set_cache_(self, attr): if attr in ("path", "_url", "_branch_path"): reader = self.config_reader() self.path = reader.get("path") # raw .gitmodules value ``` and GitPython's own containment guard is applied in only two of the places that consume it: ``` 400: def _to_relative_path(cls, parent_repo, path) # the guard (abspath + commonpath containment) 542: path = cls._to_relative_path(repo, path) # add() — guarded 1041: module_checkout_path = self._to_relative_path(self.repo, module_path) # move() — guarded ``` `update()` validates only the name and then uses the path-derived absolute location directly: ``` 788: self._validated_name(self.name) # NAME only 801: checkout_module_abspath = self.abspath # derived from self.path — unguarded 821: os.makedirs(checkout_module_abspath, exist_ok=True) ``` So `path = ../../../tmp/escaped` in an attacker-authored `.gitmodules` selects the directory that gets created and, on the clone path, populated from the submodule URL. The same absolute location is what `force_remove` hands to `shutil.rmtree`. The asymmetry is the argument: this is not a missing concept — the project wrote `_to_relative_path()` precisely for this, and `add()`/`move()` use it. `update()` does not. ## Honest limits (please read before rating) - **The most common flow is not affected.** `Repo.clone_from(...)` → `repo.submodules` → `sm.update(init=Tr

Properties

ghsa_id
GHSA-59cr-6r3x-644w
severity
medium
summary
GitPython submodule update path traversal can write outside the repository
last_source
GitHub Advisory Database
cve_id
GHSA-59cr-6r3x-644w
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
true
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T23:47:12Z
source_url
https://github.com/advisories/GHSA-59cr-6r3x-644w
ghsa_updated
2026-09-30T23:47:14Z

Related Entities (5)

VULNERABLE_TO (1)

←[Software]pip/GitPython

AFFECTS (1)

→[Software]pip/GitPython

HAS_WEAKNESS (2)

→[Weakness]External Control of File Name or Path
→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-59cr-6r3x-644w — Ninja Signal Threat Intelligence | Ninja Signal