Snowflake cli: GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination (CVE-2026-78677)
CVE-2026-78677 is a high-severity vulnerability in GitPython used by snowflake-cli, where the clone_from() and clone() methods omit the --separate-git-dir option from their unsafe options denylist. This omission allows an attacker to specify an arbitrary path for the .git metadata directory outside the intended clone destination, enabling arbitrary directory and file creation controlled by the attacker within the filesystem permissions of the running process. The flaw arises from a denylist parity gap between clone and init commands, despite documentation stating the option should be blocked by default. A fix is available for affected versions.
AI Analysis
Technical Summary
GitPython's Repo.clone_from() and Repo.clone() methods forward keyword arguments to the underlying git clone command, filtering unsafe options via a denylist (Repo.unsafe_git_clone_options). However, this denylist omits the --separate-git-dir option, which redirects the repository's .git metadata directory to an arbitrary path. Although the documentation states that allow_unsafe_options=False (default) should block this option, it is not included in the denylist, allowing an attacker who controls input to pass separate_git_dir to clone_from()/clone() and cause git to create repository metadata outside the intended destination. This can lead to arbitrary directory and file creation at attacker-controlled locations, bounded only by filesystem permissions. The root cause is a parity gap between denylist entries for clone and init commands, with the latter correctly blocking --separate-git-dir. This vulnerability is similar in nature to previously published GitPython issues where denylist omissions allowed unsafe options. The affected versions are snowflake-cli versions >=3.4.1 and <3.27.0. The CVSS 3.1 score is 7.5 (High).
Potential Impact
An attacker able to supply a separate_git_dir argument to GitPython's clone_from() or clone() methods can cause arbitrary creation of git repository metadata directories and files at any filesystem path writable by the process. This enables placing git hooks or other repository files outside the intended clone destination, potentially leading to unauthorized code execution or persistence mechanisms depending on the environment. The impact is limited by the permissions of the process running GitPython but can be significant in multi-tenant or CI/build environments.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to a fixed version of snowflake-cli that includes the corrected denylist for unsafe git clone options. Until patched, avoid passing the separate_git_dir or separate-git-dir option to Repo.clone_from() or Repo.clone(), and do not set allow_unsafe_options=True unless absolutely necessary and safe. Review any applications or services that expose git clone options to clients to ensure they do not allow this parameter. Follow vendor advisories for official patch releases and remediation guidance.
Snowflake cli: GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination (CVE-2026-78677)
Description
CVE-2026-78677 is a high-severity vulnerability in GitPython used by snowflake-cli, where the clone_from() and clone() methods omit the --separate-git-dir option from their unsafe options denylist. This omission allows an attacker to specify an arbitrary path for the .git metadata directory outside the intended clone destination, enabling arbitrary directory and file creation controlled by the attacker within the filesystem permissions of the running process. The flaw arises from a denylist parity gap between clone and init commands, despite documentation stating the option should be blocked by default. A fix is available for affected versions.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GitPython's Repo.clone_from() and Repo.clone() methods forward keyword arguments to the underlying git clone command, filtering unsafe options via a denylist (Repo.unsafe_git_clone_options). However, this denylist omits the --separate-git-dir option, which redirects the repository's .git metadata directory to an arbitrary path. Although the documentation states that allow_unsafe_options=False (default) should block this option, it is not included in the denylist, allowing an attacker who controls input to pass separate_git_dir to clone_from()/clone() and cause git to create repository metadata outside the intended destination. This can lead to arbitrary directory and file creation at attacker-controlled locations, bounded only by filesystem permissions. The root cause is a parity gap between denylist entries for clone and init commands, with the latter correctly blocking --separate-git-dir. This vulnerability is similar in nature to previously published GitPython issues where denylist omissions allowed unsafe options. The affected versions are snowflake-cli versions >=3.4.1 and <3.27.0. The CVSS 3.1 score is 7.5 (High).
Potential Impact
An attacker able to supply a separate_git_dir argument to GitPython's clone_from() or clone() methods can cause arbitrary creation of git repository metadata directories and files at any filesystem path writable by the process. This enables placing git hooks or other repository files outside the intended clone destination, potentially leading to unauthorized code execution or persistence mechanisms depending on the environment. The impact is limited by the permissions of the process running GitPython but can be significant in multi-tenant or CI/build environments.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade to a fixed version of snowflake-cli that includes the corrected denylist for unsafe git clone options. Until patched, avoid passing the separate_git_dir or separate-git-dir option to Repo.clone_from() or Repo.clone(), and do not set allow_unsafe_options=True unless absolutely necessary and safe. Review any applications or services that expose git clone options to clients to ensure they do not allow this parameter. Follow vendor advisories for official patch releases and remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-snowflake-cli-CVE-2026-78677
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abb41adf7a7c54106cc3a66
Added to database: 09/29/2026, 04:42:21 UTC
Last enriched: 09/29/2026, 05:01:02 UTC
Last updated: 09/29/2026, 05:01:02 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.