{"id":"CVE-2026-67325","aliases":["GHSA-2f96-g7mh-g2hx"],"url":"https://o3.security/vulnerability/CVE-2026-67325","summary":"GitPython before 3.1.51 Command Injection via option prefix abbreviation","details":"GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.","published":"2026-08-01T12:22:16.817Z","modified":"2026-09-05T03:48:03.717463482Z","cvss":null,"epss":{"score":0.01854,"percentile":0.77759,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"gitpython","fixedVersion":"3.1.51"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67325.json"},{"type":"ADVISORY","url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2f96-g7mh-g2hx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67325"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gitpython-before-command-injection-via-option-prefix-abbreviation"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-05T03:48:03.717463482Z"}}