What is CVE-2026-69097?
CVE-2026-69097 is a vulnerability in GitPython versions before 3.1.53, caused by improper escaping of section names in git config files. Attackers can inject arbitrary directives like 'core.sshCommand' into the victim's .git/config via malicious submodule names, potentially leading to remote code execution. Upgrading to GitPython 3.1.53 or later is recommended.
Azərbaycanca: CVE-2026-69097 GitPython kitabxanasının 3.1.53-dən əvvəlki versiyalarında git konfiqurasiya fayllarında bölmə adlarını düzgün qaçırmaması zəifliyidir. Təcavüzkar 'core.sshCommand' kimi təhlükəli direktivləri qurbanın .git/config faylına yeridə bilər, bu da uzaqdan kod icrasına səbəb ola bilər. GitPython-u 3.1.53 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
In which library does CVE-2026-69097 exist and which versions are affected?
CVE-2026-69097 affects GitPython library versions prior to 3.1.53.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.