What is CVE-2026-73622?
GitPython versions before 3.1.55 fail to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets via specially crafted URLs containing variable references. Immediate upgrade to the latest version is recommended.
Azərbaycanca: GitPython kitabxanasının 3.1.55-dən əvvəlki versiyalarında Remote.create() və Submodule.add() funksiyalarında environment variable genişlənməsi deaktiv edilmədiyi üçün uzaqdan kod ifşası zəifliyi mövcuddur. Təcavüzkar xüsusi hazırlanmış URL vasitəsilə mühit dəyişənlərini oxuya bilər. Dərhal GitPython-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which GitPython versions are affected by CVE-2026-73622?
GitPython versions before 3.1.55 are affected by this vulnerability.
How to mitigate CVE-2026-73622?
Immediate upgrade to the latest version of GitPython is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.