Red Hat disclosed two Important GitPython vulnerabilities, CVE-2026-42215 and CVE-2026-42284, that can let attackers achieve arbitrary command execution when applications pass untrusted input into Git operations. CVE-2026-42215 stems from incomplete filtering of dangerous Git options supplied through crafted Python keyword arguments, affecting functions such as Repo.clone_from(), Remote.fetch(), Remote.pull(), and Remote.push(). CVE-2026-42284 affects the _clone() path and allows malicious use of the multi_options parameter to inject Git configuration like core.hooksPath, enabling execution of attacker-controlled hooks during clone operations.
The flaws map to CWE-88 argument injection, a weakness in which applications fail to properly neutralize argument delimiters and unintended options are interpreted by downstream commands. Red Hat assigned both issues a CVSS v3 score of 7.5, while external scoring for CVE-2026-42284 ranged higher, and said no acceptable mitigation is currently available under its product security criteria. Red Hat listed multiple products as affected, with some marked not affected or will not fix, and noted that GitPython 3.1.47 contains the upstream fix for CVE-2026-42215; the disclosures underscore the risk of passing user-controlled values into command or clone parameters without strict validation or argument separation.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat last modified its CVE-2026-42284 entry, including affected product status, severity scoring differences, and the statement that no acceptable mitigation is currently available under its product security criteria.
Red Hat last modified its CVE-2026-42215 entry, retaining details on affected and unaffected products, severity, and the lack of an acceptable mitigation under its product security criteria.
Red Hat published an advisory for CVE-2026-42284, describing an Important GitPython flaw in the _clone() function where malicious multi_options input can inject Git configuration such as core.hooksPath and trigger attacker-controlled hooks during clone operations.
Red Hat published an advisory for CVE-2026-42215, describing an Important GitPython vulnerability in which crafted keyword arguments can bypass safeguards in functions such as Repo.clone_from(), Remote.fetch(), Remote.pull(), and Remote.push() to enable arbitrary command execution.
MITRE's CWE Content Team updated the CWE-88 entry's applicable platforms and relationships as part of ongoing maintenance of the weakness definition.
MITRE's CWE Content Team updated the CWE-88 entry's observed examples, reflecting maintenance of the weakness record and its mapped real-world examples.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.