#1143454 python-git: CVE-2026-67322 CVE-2026-67323 CVE-2026-67324 CVE-2026-67325

Package:
src:python-git
Source:
src:python-git
Submitter:
Salvatore Bonaccorso
Date:
2026-09-01 00:37:03 UTC
Severity:
normal
Tags:
#1143454#5
Date:
2026-08-02 05:23:57 UTC
From:
To:
Hi,

The following vulnerabilities were published for python-git.

CVE-2026-67322[0]:
| GitPython before 3.1.52 is vulnerable to environment-variable
| exfiltration in Repo.clone_from(). The caller-supplied remote URL is
| passed through Git.polish_url(), which on non-Cygwin platforms calls
| os.path.expandvars() on the URL before invoking git clone. An
| attacker who controls the clone URL can embed $NAME or ${NAME}
| tokens that are expanded to the values of the hosting process's
| environment variables (e.g., AWS_SECRET_ACCESS_KEY or GITHUB_TOKEN).
| The resulting URL, now containing the secret, is transmitted over
| the network to an attacker-controlled host during the clone attempt,
| disclosing the secret.


CVE-2026-67323[1]:
| GitPython before 3.1.51 fails to guard against dangerous Git options
| passed as keyword arguments in Repo.archive() and git.ls_remote(),
| allowing command injection via options such as --exec/--upload-pack
| (leading to arbitrary command execution). Additionally,
| Repo.iter_commits() and Repo.blame() do not check for leading-dash
| revision arguments, so a revision like --output=<path> can cause Git
| to open and truncate an arbitrary file. Exploitation requires an
| application that passes attacker-controlled arguments to these
| methods.


CVE-2026-67324[2]:
| GitPython 3.1.50 fails to recognize joined short-option forms such
| as -u<value> (the short form of --upload-pack=<value>) when
| enforcing its default unsafe-option gate. When an application passes
| attacker-influenced clone options into Repo.clone_from(...,
| multi_options=..., allow_unsafe_options=False), an attacker can
| supply -u<helper> to bypass the gate that blocks --upload-pack/-u,
| causing Git to execute the specified helper command during clone.
| Fixed in 3.1.51.


CVE-2026-67325[3]:
| GitPython before 3.1.51 contains an incomplete command injection
| blocklist that fails to account for git's long-option prefix
| abbreviation feature. Attackers can bypass the unsafe options guard
| by using abbreviated option names like upload_p instead of
| upload_pack, which git resolves to dangerous options and executes
| arbitrary commands.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-67322
https://www.cve.org/CVERecord?id=CVE-2026-67322
[1] https://security-tracker.debian.org/tracker/CVE-2026-67323
https://www.cve.org/CVERecord?id=CVE-2026-67323
[2] https://security-tracker.debian.org/tracker/CVE-2026-67324
https://www.cve.org/CVERecord?id=CVE-2026-67324
[3] https://security-tracker.debian.org/tracker/CVE-2026-67325
https://www.cve.org/CVERecord?id=CVE-2026-67325

Regards,
Salvatore

#1143454#10
Date:
2026-09-01 00:34:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-git, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143454@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emmanuel Arias <eamanu@debian.org> (supplier of updated python-git package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 31 Aug 2026 21:04:23 -0300
Source: python-git
Architecture: source
Version: 3.1.61-1
Distribution: unstable
Urgency: high
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Emmanuel Arias <eamanu@debian.org>
Closes: 1143454 1143602 1144344 1144929 1145672
Changes:
 python-git (3.1.61-1) unstable; urgency=high
 .
   * Team upload.
   * New upstream version 3.1.61.
     - Fix CVE-2026-67323, CVE-2026-67324, CVE-2026-67325, CVE-2026-67322,
       CVE-2026-69097, CVE-2026-73623, CVE-2026-73624, CVE-2026-73625,
       CVE-2026-73622, CVE-2026-73621, CVE-2026-73619, CVE-2026-73620,
       CVE-2026-76217, CVE-2026-76218, CVE-2026-76219, CVE-2026-76220,
       CVE-2026-76221, CVE-2026-76222, CVE-2026-78675, CVE-2026-78676,
       CVE-2026-78677, CVE-2026-78678, CVE-2026-78679 (Closes: #1143454,
       #1143602, #1144344, #1144929, #1145672)
   * d/tests/control: Add procps to the autopkgtest dependencies.
Checksums-Sha1:
 aee695ae6710f3259917dff61402c23a6cc48ffc 2798 python-git_3.1.61-1.dsc
 a0d48c24a098aa3437ea3524b3095e3d65618c67 1022655 python-git_3.1.61.orig.tar.gz
 5fd8979e50dbe3ce029237490547254d02b7ef6f 7332 python-git_3.1.61-1.debian.tar.xz
 7a3a8741d51ab103eadec2eaa337b7e661ab7f24 8174 python-git_3.1.61-1_amd64.buildinfo
Checksums-Sha256:
 4dac291bf776a187d1f211780f6e80fe36654fe3f668e8d0177b16a6c6369bb0 2798 python-git_3.1.61-1.dsc
 e919636aa7a259f9d9ece36037380b70262c7b76e6e93346be13fa0c23cda997 1022655 python-git_3.1.61.orig.tar.gz
 cf75d0e27114f71cfe5f61582104f9f2a5fb904a46c1f20cff60a67ce38f1062 7332 python-git_3.1.61-1.debian.tar.xz
 551a06eec67c03aeb2f08ce5812206e98e20af81f0d048db5a61913a34eadc2b 8174 python-git_3.1.61-1_amd64.buildinfo
Files:
 d9edf33bd778b4cc68fbba90b8a29c14 2798 python optional python-git_3.1.61-1.dsc
 4b2374b7714c18ef801dea5bccb2c5f4 1022655 python optional python-git_3.1.61.orig.tar.gz
 ed9f37cb6e1b66441d9ba96a9b2411b5 7332 python optional python-git_3.1.61-1.debian.tar.xz
 25928b55bbec50f03910085555ba12dc 8174 python optional python-git_3.1.61-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJGBAEBCgAwFiEEE3lnVbvHK7ir4q61+p3sXeEcY/EFAmqWF8sSHGVhbWFudUBk
ZWJpYW4ub3JnAAoJEPqd7F3hHGPx/swQAL1PlG7fMLHGnyCEG6pQLRILniXDQ3xw
aRmH2T2JxYsnKb7JoNBhCqpzqrfUGS98gA/iN+a6ZuNBypZkOPdh/hXH/WY8O3Ma
79SurPprRe+eTAT1J6oXyR+MgwuGt/nIpnD6XQWV4gjkIXurC2pejfBtDqYOTxgj
rmlY9zJOsKFNe1CEK9HkY+JsYiu5AfBm5oUbeDZiU50bpjT8ZJXWqLexMS+hCCHA
hGmnKZEUxPYjcdxbp3li2fy7y2bWvb5Ty85fWFhcMGVDiAgTeAYYa/YSHJO3k0+0
3EK3W07rbZbBjjm8iYAIupeyboocxd6ellWPoBucK4psfybpCqUGsFii0ex1UAwj
uMdrxdbOgWfD+aC+3oRPF9IIguJ63FqV2gNs+fJGKudlTU8X4TRy8D9YcG0/+/a3
EmuZ1HUtOsy+wvd1ol6r0geOwXWleYRNpANK2czzRq8Yb0hjSnn0zw/3YfCifLTr
2gT9Was29RXiVGTgjnQ2UuiaSonaTpBh1Dl0Owo6RPQCNfJDRHGUPWq/gX7h0vWQ
VAJs5fv/VsyhCOaIb76zT2YE+x1X8seW/hnnCH2aFCXKxxCOsI7N/9yEpYvktuic
6TE8y7G6YvDCgHZ0qU27N9vC6CMyTpRKw7IjIL7X65xy5en3WGf6adlL/78NP2Qr
Nmy/1wuP8Zn7
=5GyX
-----END PGP SIGNATURE-----