Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-67326

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 24.5%
CVSS Severity
CVSS v3 Score 7.0
Products affected by CVE-2026-67326


Contact Us

Shodan ® - All rights reserved