CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unkn

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https:// radar.offseq.com/threat/cve-20 26-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe # OffSeq # CVE2026786

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unkn

mastodon:infosec-exchangeother36d ago kagi ↗

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https:// radar.offseq.com/threat/cve-20 26-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe # OffSeq # CVE2026786