Snowflake cli: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython (CVE-2026-76222)
GitPython versions used by the Snowflake CLI contain a vulnerability (CVE-2026-76222) where an attacker-controlled submodule name in a cloned repository's .gitmodules file can cause GitPython to create a Git repository outside the intended working directory. This occurs because GitPython does not validate submodule names for path traversal sequences, unlike core Git. The vulnerability requires a victim to clone a malicious repository and run submodule initialization via GitPython. It can lead to arbitrary Git repository creation at attacker-chosen filesystem paths, potentially impacting integrity. A fix is available for affected versions.
AI Analysis
Technical Summary
GitPython computes the on-disk location for submodules from the .gitmodules section name without validating it. An attacker can craft a repository with a submodule name containing path traversal sequences (e.g., '../../../../some/path'), causing GitPython to create and initialize a full Git repository outside the intended clone directory when submodule initialization is performed. This vulnerability arises because GitPython's implementation does not normalize or validate the submodule name before using it to construct filesystem paths, unlike core Git which blocks such attacks (CVE-2018-11235). The attack requires the victim to clone the malicious repository and run submodule update with init=True. Proof-of-concept demonstrates creation of repositories outside the working tree. The vulnerability affects GitPython versions used in Snowflake CLI >=3.4.1 and <3.25.0. A patch is available.
Potential Impact
An attacker controlling a Git repository that a victim clones and initializes submodules for using GitPython can cause arbitrary creation and initialization of Git repositories at attacker-chosen filesystem paths outside the intended working directory. This can lead to integrity issues by placing Git metadata and repositories in unexpected locations. There is no direct confidentiality or availability impact described. The vulnerability requires user interaction (cloning and submodule initialization) and user-level permissions. Core Git is not affected due to prior mitigations.
Mitigation Recommendations
A patch is available for this vulnerability. Users of affected GitPython versions in Snowflake CLI (>=3.4.1 <3.25.0) should upgrade to a fixed version as soon as possible. Until patched, avoid cloning and initializing submodules from untrusted repositories using GitPython. The vendor advisory confirms patch availability; apply the official fix to remediate this issue.
Snowflake cli: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython (CVE-2026-76222)
Description
GitPython versions used by the Snowflake CLI contain a vulnerability (CVE-2026-76222) where an attacker-controlled submodule name in a cloned repository's .gitmodules file can cause GitPython to create a Git repository outside the intended working directory. This occurs because GitPython does not validate submodule names for path traversal sequences, unlike core Git. The vulnerability requires a victim to clone a malicious repository and run submodule initialization via GitPython. It can lead to arbitrary Git repository creation at attacker-chosen filesystem paths, potentially impacting integrity. A fix is available for affected versions.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GitPython computes the on-disk location for submodules from the .gitmodules section name without validating it. An attacker can craft a repository with a submodule name containing path traversal sequences (e.g., '../../../../some/path'), causing GitPython to create and initialize a full Git repository outside the intended clone directory when submodule initialization is performed. This vulnerability arises because GitPython's implementation does not normalize or validate the submodule name before using it to construct filesystem paths, unlike core Git which blocks such attacks (CVE-2018-11235). The attack requires the victim to clone the malicious repository and run submodule update with init=True. Proof-of-concept demonstrates creation of repositories outside the working tree. The vulnerability affects GitPython versions used in Snowflake CLI >=3.4.1 and <3.25.0. A patch is available.
Potential Impact
An attacker controlling a Git repository that a victim clones and initializes submodules for using GitPython can cause arbitrary creation and initialization of Git repositories at attacker-chosen filesystem paths outside the intended working directory. This can lead to integrity issues by placing Git metadata and repositories in unexpected locations. There is no direct confidentiality or availability impact described. The vulnerability requires user interaction (cloning and submodule initialization) and user-level permissions. Core Git is not affected due to prior mitigations.
Mitigation Recommendations
A patch is available for this vulnerability. Users of affected GitPython versions in Snowflake CLI (>=3.4.1 <3.25.0) should upgrade to a fixed version as soon as possible. Until patched, avoid cloning and initializing submodules from untrusted repositories using GitPython. The vendor advisory confirms patch availability; apply the official fix to remediate this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-snowflake-cli-CVE-2026-76222
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abb41adf7a7c54106cc3a68
Added to database: 09/29/2026, 04:42:21 UTC
Last enriched: 09/29/2026, 05:01:13 UTC
Last updated: 09/29/2026, 18:13:11 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.