CVE-2026-73622
PYSEC-2026-3951 · CVE-2026-73622 · GHSA-94p4-4cq8-9g67
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacker-controlled hosts during fetch or pull operations.
References
- ADVISORY https://www.vulncheck.com/advisories/gitpython-before-environment-variable-exfiltration-via-remote-add
- FIX https://github.com/gitpython-developers/GitPython/commit/8ac5a30519b6f4af85398b9b9d7064ff4d452da2
- EVIDENCE https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-94p4-4cq8-9g67
Ready to move
Start Securing
Free, no credit card | First findings in minutes