Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-67323

CVE-2026-67323: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.4

    High [CVE-2026-67323] Arbitrary code execution via command injection due to unguarded Git options

    CVE-2026-67323Source published Source updated

    GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output= can cause Git to open and truncate an arbitrary file. Exploitation requires an application that passes attacker-controlled arguments to these methods. This vulnerability allows an attacker to inject arbitrary commands when using functions like Repo.archive() and git.ls_remote(), potentially leading to arbitrary code execution. This is an Important vulnerability because it allows for arbitrary code execution or file…

    Affected products in this advisory
    • Red Hat Ansible Automation Platform 2.5 for RHEL 8
    • Red Hat Ansible Automation Platform 2.5 for RHEL 9
    • Red Hat Ansible Automation Platform 2.6 for RHEL 9
    • Red Hat Ansible Automation Platform 2.7

    11 more entries in the full advisory.

    Source-reported affected versions
    • < 3.1.51
    Source-reported fixed versions
    • python3.12-gitpython-0:3.1.59-1.el8ap
    • automation-controller-0:4.6.33-1.el8ap
    • python3.12-gitpython-0:3.1.59-1.el9ap
    • automation-controller-0:4.6.33-1.el9ap

    46 more entries in the full advisory.

    Mitigation guidance
    • To mitigate the risk, ensure that applications utilizing GitPython are run within a sandboxed environment with minimal privileges. This limits the potential impact of arbitrary command execution or file truncation if an attacker successfully exploits the vulnerability through an application processing untrusted input. Review applications that interact with GitPython to ensure all input is properly sanitized and validated before being passed to methods such as Repo.archive(), git.ls_remote(), Repo.iter_commits(), or Repo.blame().

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery