CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100689

MEDIUMCVSS 5.9NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPython's own containment guard Submodule._to_relative_path() is

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100689 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100689

MEDIUMCVSS 5.9NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPython's own containment guard Submodule._to_relative_path() is

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]