OESA-2026-3354

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3354
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3354.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3354
Upstream
Published
2026-08-13T14:00:34Z
Modified
2026-08-16T01:45:12.080066678Z
Severity
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
python-GitPython security update
Details

GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing.

Security Fix(es):

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via createsubmodule or clonefrom operations, achieving remote code execution when git performs ssh operations.(CVE-2026-69097)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / python-GitPython

Package

Name
python-GitPython
Purl
pkg:rpm/openEuler/python-GitPython&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.57-1.oe2403sp3

Ecosystem specific

{
    "src": [
        "python-GitPython-3.1.57-1.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "python-GitPython-help-3.1.57-1.oe2403sp3.noarch.rpm",
        "python3-GitPython-3.1.57-1.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3354.json"