CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-P538-C434-8V24

GHSA-P538-C434-8V24: Arbitrary File Truncation via Argument Injection in GitPython Commit.count

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 4, 2026·5 min read·45 visits

Executive Summary (TL;DR)

Unsafe forwarding of keyword arguments in GitPython's Commit.count method allows remote attackers to inject command-line flags like --output, causing arbitrary files on the local filesystem to be truncated to zero bytes.

GitPython prior to version 3.1.56 is vulnerable to argument injection in the Commit.count method. An attacker who controls keyword arguments passed to this method can inject arbitrary Git options, such as --output, leading to arbitrary file truncation on the host filesystem.

Vulnerability Overview

GitPython is an open-source Python library used to interact with Git repositories by programmatically wrapping the Git command-line binary. The library abstracts Git CLI commands into high-level Python objects, facilitating repository management, commit inspection, and history traversal.

Within this architecture, the Commit.count method is designed to count the number of commits reachable from a specific reference. To provide flexibility, the method dynamically forwards arbitrary keyword arguments to the underlying Git command execution layer.

This implementation exposes an argument injection attack surface. If an application forwards untrusted user input directly as keyword arguments into Commit.count, an attacker can inject arbitrary command-line parameters. Specifically, injecting the --output option instructs the Git binary to write command output to a specified target file, causing the system to truncate that file immediately.

Root Cause Analysis

The root cause of GHSA-P538-C434-8V24 is improper input validation (CWE-20) combined with argument injection (CWE-88) in git/objects/commit.py. The Commit.count method accepted raw keyword arguments (**kwargs) and forwarded them directly to the underlying execution process without validation.

When GitPython translates Python keyword arguments to Git CLI arguments, a key-value pair such as {"output": "/path/to/file"} is converted into --output=/path/to/file. While sibling APIs in GitPython implemented safety checks via Git.check_unsafe_options to filter out dangerous flags, the Commit.count method was left entirely unguarded.

When the underlying binary executes git rev-list --output=/path/to/file, the Git process immediately initiates a file write handle on the target path. As part of this standard file system operation, the target file is truncated to zero bytes before any commit logic is processed. This behavior is native to the Git binary and occurs regardless of the validity of the rest of the command execution.

Code Analysis

The vulnerability exists in the count method of the Commit class in git/objects/commit.py. Below is the vulnerable implementation where **kwargs are forwarded to the Git command execution without any filtering:

# Vulnerable implementation in git/objects/commit.py
def count(self, paths: Union[PathLike, Sequence[PathLike]] = "", **kwargs: Any) -> int:
    # Raw kwargs are directly forwarded without validation
    # ...

The security patch introduced in version 3.1.56 remediates this vulnerability by validating input options against a known blacklist of unsafe parameters. The following diff highlights the remediation steps implemented by the maintainers:

@@ -269,13 +269,21 @@ def summary(self) -> Union[str, bytes]:
         else:
             return self.message.split(b"\n", 1)[0]
 
-    def count(self, paths: Union[PathLike, Sequence[PathLike]] = "", **kwargs: Any) -> int:
+    def count(
+        self,
+        paths: Union[PathLike, Sequence[PathLike]] = "",
+        allow_unsafe_options: bool = False,
+        **kwargs: Any,
+    ) -> int:
         """Count the number of commits reachable from this commit.
 
         :param paths:
             An optional path or a list of paths restricting the return value to commits
             actually containing the paths.
 
+        :param allow_unsafe_options:
+            Allow unsafe options, like ``--output``.
+
         :param kwargs:
             Additional options to be passed to :manpage:`git-rev-list(1)`.
         """
+        if not allow_unsafe_options:
+            Git.check_unsafe_options(
+                options=Git._option_candidates([], kwargs), unsafe_options=self.unsafe_git_rev_options
+            )
+
         if paths:

This modification adds a default-false allow_unsafe_options parameter. When false, the method extracts command candidates and validates them against the self.unsafe_git_rev_options collection, effectively blocking dangerous options such as --output.

Exploitation Methodology

An attack requires that an application dynamically accepts user-controlled inputs and translates them into keyword arguments unpacked within the Commit.count method. The threat model typically involves an application exposing a web API that permits query parameter customization.

During exploitation, the attacker supplies a key-value pair where the key is set to output and the value is the path of a sensitive system or application file. The application unpacks these arguments directly into the method call.

Upon invocation, the library spawns the git rev-list command with the --output parameter. The operating system's file system handler, driven by the Git binary's initialization process, immediately empties the content of the target file to prepare it for writing. This sequence completes before any verification or commit counting occurs.

Impact Assessment

The security impact of GHSA-P538-C434-8V24 is high regarding integrity and availability, while maintaining low confidentiality impact. By exploiting this flaw, an unauthenticated attacker can disable services, corrupt configurations, or clear critical log archives on the hosting environment.

If the application process runs with elevated privileges, such as root or Administrator, the attacker can truncate system-critical files like /etc/hosts, systemd service files, or application binaries. This results in immediate denial of service or system instability.

In containerized environments or CI/CD pipelines, this vulnerability can be leveraged to corrupt build states or clear environment variables. Because GitPython is commonly integrated into automation frameworks, the potential radius of impact spans multiple connected systems.

Remediation and Bypasses

The definitive remediation is upgrading GitPython to version 3.1.56 or higher. This update enables the default option validation, raising an UnsafeOptionError if an unsafe parameter is supplied.

If immediate upgrade is not feasible, implement strict input sanitization on all dynamically generated keyword arguments before they are passed to GitPython. Applications must sanitize and filter input dictionaries to ensure no blacklisted keys, such as output, are allowed.

Additionally, developers must evaluate whether downstream parameters can bypass validation. For instance, passing malicious inputs through positional array parameters like paths could still result in option injection if the command builder fails to cleanly separate arguments using double dashes. Ensuring strict parameter isolation is vital for complete defense.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10

Affected Systems

GitPython

Affected Versions Detail

Product
Affected Versions
Fixed Version
GitPython
gitpython-developers
< 3.1.563.1.56
AttributeDetail
CWE IDCWE-88 (Improper Control of Generation of Code / Argument Injection)
Attack VectorLocal/Remote parameter injection
CVSS Score7.5 (High)
EPSS ScoreN/A
ImpactArbitrary File Truncation
Exploit StatusPoC Available
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1211Exploitation for Defense Evasion
Defense Evasion
T1499Endpoint Denial of Service
Impact

Vulnerability Timeline

Security patch committed to GitPython main repository.
2026-07-25
GitPython version 3.1.56 tagged and released.
2026-07-25
GitHub Advisory GHSA-P538-C434-8V24 published.
2026-07-25

References & Sources

  • [1]Official GitHub Advisory
  • [2]Official GitPython Pull Request
  • [3]Official Patch Commit
  • [4]Official Release Notes

More Reports

•19 minutes ago•CVE-2026-107720
7.4

CVE-2026-107720: Signature Verification Bypass in NearForm fast-jwt

CVE-2026-107720 is a critical signature verification bypass vulnerability in NearForm's fast-jwt Node.js library. Under specific configurations where the token verifier is initialized with a falsy cryptographic key (such as an empty string or null) and a non-empty algorithms allowlist, the library erroneously skips signature validation. This allows unauthenticated remote attackers to submit fabricated, unsigned JSON Web Tokens and bypass the authorization boundary of the application entirely.

Amit Schendel
Amit Schendel
2 views•7 min read
•about 1 hour ago•CVE-2026-107715
6.8

CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections

Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session Cookies) are dynamically re-applied to the subsequent request, bypassing the internal header-stripping logic. An attacker who controls a redirection endpoint can capture sensitive bearer tokens or cookies.

Alon Barad
Alon Barad
5 views•7 min read
•about 2 hours ago•CVE-2026-107399
6.8

CVE-2026-107399: Information Disclosure via HTML Meta-Refresh in Ruby Mechanize

An origin trust boundary failure in the Ruby mechanize library (prior to v2.14.1) allows unauthenticated remote web servers to harvest sensitive global request headers, such as Authorization Bearer tokens and cookies, by utilizing HTML-level meta-refresh redirection tags. Standard HTTP-level redirect boundaries were not applied to document-level redirects, creating a vector for cross-origin credential leakage during automated crawls.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 3 hours ago•CVE-2026-107718
6.1

CVE-2026-107718: Open Redirect Vulnerability in @adonisjs/http-server

CVE-2026-107718 is a medium-severity Open Redirect vulnerability in the core HTTP server package of the AdonisJS Node.js framework. Prior to versions 8.2.3 and 9.3.0, the framework built route paths by directly interpolating dynamic parameters and wildcard segments without URI encoding. If an application routes attacker-controlled input directly to a dynamic first path segment and uses the generated route URL as a redirect destination, a leading slash can produce a scheme-relative external URL. Modern web browsers process scheme-relative URLs by redirecting the client to the specified external domain, exposing users to credential harvesting, social engineering, and session hijacking. This vulnerability affects all applications running unpatched configurations where input validation is not explicitly implemented before generating paths.

Alon Barad
Alon Barad
5 views•6 min read
•about 4 hours ago•CVE-2026-107725
8.7

CVE-2026-107725: Remote Code Execution via Authorization Bypass in Hazelcast Predicates API

CVE-2026-107725 is a critical security bypass in Hazelcast where missing authorization checks in the MapPermission class permit unprivileged clients to issue queries containing aggregators or projections. This architectural oversight allows attackers to run arbitrary code on the cluster servers under the privileges of the active Hazelcast process.

Amit Schendel
Amit Schendel
6 views•7 min read
•about 5 hours ago•CVE-2026-107396
5.4

CVE-2026-107396: Stored Cross-Site Scripting (XSS) in Indico

A stored Cross-Site Scripting (XSS) vulnerability was identified in Indico, an open-source event management system developed at CERN, prior to version 3.3.13. The vulnerability stems from weak URL validation in custom link fields and lack of HTML sanitization during Marshmallow serialization of event notes. This allows authenticated attackers with event modification privileges to inject malicious payloads that execute in the browser of users viewing the event pages or collaborating on notes.

Alon Barad
Alon Barad
4 views•6 min read