SUSE-SU-2026:21813-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621813-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21813-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:21813-1
Upstream
CVE (4)
Related
Published
2026-05-18T09:43:07Z
Modified
2026-05-28T18:24:03Z
Summary
Security update for python-GitPython
Details

This update for python-GitPython fixes the following issues

  • CVE-2026-42215: command injection via Git options bypass (bsc#1264604).
  • CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605).
  • CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository (bsc#1264606).
  • CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608).
References

Affected packages