{"id":"GHSA-jm78-9fvv-mhgr","summary":"GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)","details":"## Summary\nGitPython's config-name validator only neutralizes CR/LF/NUL for the `\"option\"` label; it does not reject `=`, `#`, `;`, `[`, `]`, or whitespace in an **option name**. `write_section` writes the option name verbatim into the config file, so an option name such as `sshCommand = touch \u003ccmd\u003e #` is written as `\\tsshCommand = touch \u003ccmd\u003e # = \u003cvalue\u003e`, which git parses as `core.sshCommand = touch \u003ccmd\u003e` (the trailing `#` comments out the intended value). This forges arbitrary config directives (`core.sshCommand`, `core.hooksPath`, `alias.*`) → RCE on the next git operation. This is a distinct field (option name, not section name) and distinct character class (`=`/`#`/space, not newline/bracket) from GHSA-3rp5-jjmw-4wv2 (section-name bracket injection) and GHSA-mv93-w799-cj2w / GHSA-v87r-6q3f-2j67 (newline injection).\n\n## Root Cause\n`_assure_config_name_safe(name, label)` (`git/config.py:897`) applies the bracket/quote state machine ONLY when `label == \"section\"`; for the `\"option\"` label it falls through with just the `UNSAFE_CONFIG_CHARS_RE = [\\r\\n\\x00]` regex. `write_section` then writes the option name verbatim into `\"\\t%s = %s\\n\"` (config.py:702).\n\n## Impact\nArbitrary git-config directive injection → remote code execution via `core.sshCommand` (fires on any ssh git operation, no staged file needed) or `core.hooksPath` (with a staged hook). Requires the embedding application to forward a caller-influenced OPTION NAME into the config writer (name-control model, the same name-control model accepted by the related published advisories GHSA-3rp5-jjmw-4wv2 and GHSA-mv93-w799-cj2w). Default configuration.\n\n## Proof of Concept\n```python\nwith repo.config_writer() as cw:\n    cw.set_value(\"core\", \"sshCommand = touch /tmp/RCE #\", \"x\")\n# git config --get core.sshCommand  -\u003e  touch /tmp/RCE\n```\n\n## Attack Chain\n1. Entry: app calls config writer with attacker-controlled OPTION name: `set_value(\"core\", \"sshCommand = touch /tmp/RCE #\", \"x\")`.\n2. Check: `_assure_config_name_safe(option, \"option\")` @ config.py. Guard: regex matches only `[\\r\\n\\x00]`; bracket/quote state machine is gated on `label==\"section\"`. Bypass proof: `=`,`#`,space pass → no `ValueError`.\n3. Sink: `write_section` writes `\"\\tsshCommand = touch /tmp/RCE # = x\\n\"` (config.py:702).\n4. Impact: git parses `core.sshCommand=touch /tmp/RCE` → arbitrary code execution on next git op.\n\n## Bypass Evidence\nIndependently reproduced (gate harness): `set_value('core','sshCommand = touch \u003cRCE\u003e #','x')` → no `ValueError`; file line `sshCommand = touch \u003cRCE\u003e # = x`; `git config --get core.sshCommand` → `touch \u003cRCE\u003e` (rc=0). Also verified `core.hooksPath` via both `GitConfigParser` and `repo.config_writer()`. Fix-commit read: bracket/quote checks are inside `if label == \"section\"`; the `\"option\"` label is not covered.\n\n## Affected Versions\n`GitPython \u003c= 3.1.57` (validator present verbatim on the latest release tag).\n\n## Suggested Fix\nApply the section-name safety checks (reject `=`, `#`, `;`, `[`, `]`, whitespace) to the `\"option\"` label as well, or validate the fully-rendered config line after substitution.\n\n---\nReported by **zx (Jace)** — GitHub: @manus-use","aliases":["CVE-2026-76221","PYSEC-2026-3783"],"modified":"2026-09-10T03:51:14.296736368Z","published":"2026-08-07T15:46:35Z","database_specific":{"github_reviewed_at":"2026-08-07T15:46:35Z","nvd_published_at":null,"cwe_ids":["CWE-74","CWE-88"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgr"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/pull/2204"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/commit/a495ccd3b547ccd60b2187215823b72a9c0188bf"},{"type":"PACKAGE","url":"https://github.com/gitpython-developers/GitPython"},{"type":"WEB","url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.58"}],"affected":[{"package":{"name":"gitpython","ecosystem":"PyPI","purl":"pkg:pypi/gitpython"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.58"}]}],"versions":["0.1.7","0.2.0-beta1","0.3.0-beta1","0.3.0-beta2","0.3.1-beta2","0.3.2","0.3.2.1","0.3.2.RC1","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7","1.0.0","1.0.1","1.0.2","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.0.9.dev0","2.0.9.dev1","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.15","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.1","3.1.10","3.1.11","3.1.12","3.1.13","3.1.14","3.1.15","3.1.16","3.1.17","3.1.18","3.1.19","3.1.2","3.1.20","3.1.22","3.1.23","3.1.24","3.1.25","3.1.26","3.1.27","3.1.28","3.1.29","3.1.3","3.1.30","3.1.31","3.1.32","3.1.33","3.1.34","3.1.35","3.1.36","3.1.37","3.1.38","3.1.4","3.1.40","3.1.41","3.1.42","3.1.43","3.1.44","3.1.45","3.1.46","3.1.47","3.1.48","3.1.49","3.1.5","3.1.50","3.1.51","3.1.52","3.1.53","3.1.54","3.1.55","3.1.56","3.1.57","3.1.6","3.1.7","3.1.8","3.1.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.57","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jm78-9fvv-mhgr/GHSA-jm78-9fvv-mhgr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}