OESA-2026-3353

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3353
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3353.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3353
Upstream
Published
2026-08-13T14:00:33Z
Modified
2026-08-16T01:45:12.125343971Z
Severity
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
python-GitPython security update
Details

GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.

Security Fix(es):

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via createsubmodule or clonefrom operations, achieving remote code execution when git performs ssh operations.(CVE-2026-69097)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP1 / python-GitPython

Package

Name
python-GitPython
Purl
pkg:rpm/openEuler/python-GitPython&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.57-1.oe2403sp1

Ecosystem specific

{
    "src": [
        "python-GitPython-3.1.57-1.oe2403sp1.src.rpm"
    ],
    "noarch": [
        "python-GitPython-help-3.1.57-1.oe2403sp1.noarch.rpm",
        "python3-GitPython-3.1.57-1.oe2403sp1.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3353.json"