openSUSE-SU-2026:20777-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20777-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20777-1
Upstream
CVE (4)
Related
Published
2026-05-18T09:44:52Z
Modified
2026-05-26T18:24:19Z
Summary
Security update for python-GitPython
Details

This update for python-GitPython fixes the following issues

  • CVE-2026-42215: command injection via Git options bypass (bsc#1264604).
  • CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605).
  • CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository (bsc#1264606).
  • CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608).
References

Affected packages