CVE-2026-78676
CriticalAdvisory
Published 25 Aug 2026In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.004
- 36th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 54
- of 17,781 indexed, latest versions
- Container images
- 62
- deployed by those charts
- Fix available
- 1 of 1
- affected package
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 62 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gitpythonpypi | 3.1.0, 3.1.7, 3.1.11, 3.1.17+17 more | 3.1.59 | 62 |
- OSV records
- GHSA-284h-m62q-gf8w
- Also known as
- PYSEC-2026-3786
Charts affected
54 by stars
Container images carrying it
62 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| gcr.io/ | 25d6975951f1 | gitpython | 3.1.59 | 1 |
| ghcr.io/ | 8d943799621b | gitpython | 3.1.59 | 1 |
| ghcr.io/ | a2be95de450c | gitpython | 3.1.59 | 1 |
| ghcr.io/ | d6e901ad0ebd | gitpython | 3.1.59 | 1 |
| ghcr.io/ | 10d271f08ab3 | gitpython | 3.1.59 | 1 |
| ghcr.io/ | cd25a5cc3f1b | gitpython | 3.1.59 | 1 |
| ghcr.io/ | d30e631684c3 | gitpython | 3.1.59 | 1 |
| ghcr.io/ | 153b8b893232 | gitpython | 3.1.59 | 1 |
| ghcr.io/ | cdf1e3329bfe | gitpython | 3.1.59 | 1 |
| ghcr.io/ | 533ce58c6e02 | gitpython | 3.1.59 | 1 |
| quay.io/ | 65694109877e | gitpython | 3.1.59 | 1 |
| quay.io/ | 59fe607dfdf2 | gitpython | 3.1.59 | 1 |