Snowflake cli: GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE) (CVE-2026-76221)
GitPython versions up to 3.1.57 contain a vulnerability in the config-name validator that allows injection of arbitrary git configuration directives via crafted option names. This flaw permits an attacker to forge directives such as core.sshCommand or core.hooksPath, leading to remote code execution on subsequent git operations. The issue arises because the validator does not reject characters like '=', '#', or whitespace in option names, allowing malicious input to be written verbatim into the config file. This vulnerability affects applications embedding GitPython that forward attacker-controlled option names to the config writer.
AI Analysis
Technical Summary
GitPython's config-name validator only sanitizes CR, LF, and NUL characters for option names but fails to reject characters such as '=', '#', ';', '[', ']', or whitespace. When an attacker-controlled option name containing these characters is written to the git config file, it results in forged git configuration directives. For example, an option name like 'sshCommand = touch <cmd> #' is written as '\tsshCommand = touch <cmd> # = <value>', which git interprets as setting core.sshCommand to 'touch <cmd>', enabling remote code execution on the next git operation. The root cause is that the bracket/quote state machine validation applies only to section names, not option names. This vulnerability is distinct from other known injection issues in GitPython. A proof of concept demonstrates that setting such an option name results in arbitrary command execution. The vulnerability affects GitPython versions up to 3.1.57 and snowflake-cli versions >=3.4.1 <3.25.0. A patch is available that applies stricter validation to option names.
Potential Impact
An attacker able to supply a crafted option name to the GitPython config writer can inject arbitrary git configuration directives, including core.sshCommand or core.hooksPath. This leads to remote code execution when git performs subsequent operations involving SSH or hooks. The impact includes full system compromise under the context of the git operation. Exploitation requires the embedding application to forward attacker-controlled option names to the config writer. There are no known exploits in the wild at this time.
Mitigation Recommendations
A patch is available that extends the section-name safety checks to option names, rejecting unsafe characters such as '=', '#', ';', '[', ']', and whitespace. Users should upgrade GitPython to a fixed version beyond 3.1.57 and snowflake-cli outside the affected range >=3.4.1 <3.25.0. Until patched, avoid passing untrusted input as option names to the config writer. Review application code that interacts with GitPython's config writer to ensure option names are not attacker-controlled.
Snowflake cli: GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE) (CVE-2026-76221)
Description
GitPython versions up to 3.1.57 contain a vulnerability in the config-name validator that allows injection of arbitrary git configuration directives via crafted option names. This flaw permits an attacker to forge directives such as core.sshCommand or core.hooksPath, leading to remote code execution on subsequent git operations. The issue arises because the validator does not reject characters like '=', '#', or whitespace in option names, allowing malicious input to be written verbatim into the config file. This vulnerability affects applications embedding GitPython that forward attacker-controlled option names to the config writer.
CVSS v3.1
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GitPython's config-name validator only sanitizes CR, LF, and NUL characters for option names but fails to reject characters such as '=', '#', ';', '[', ']', or whitespace. When an attacker-controlled option name containing these characters is written to the git config file, it results in forged git configuration directives. For example, an option name like 'sshCommand = touch <cmd> #' is written as '\tsshCommand = touch <cmd> # = <value>', which git interprets as setting core.sshCommand to 'touch <cmd>', enabling remote code execution on the next git operation. The root cause is that the bracket/quote state machine validation applies only to section names, not option names. This vulnerability is distinct from other known injection issues in GitPython. A proof of concept demonstrates that setting such an option name results in arbitrary command execution. The vulnerability affects GitPython versions up to 3.1.57 and snowflake-cli versions >=3.4.1 <3.25.0. A patch is available that applies stricter validation to option names.
Potential Impact
An attacker able to supply a crafted option name to the GitPython config writer can inject arbitrary git configuration directives, including core.sshCommand or core.hooksPath. This leads to remote code execution when git performs subsequent operations involving SSH or hooks. The impact includes full system compromise under the context of the git operation. Exploitation requires the embedding application to forward attacker-controlled option names to the config writer. There are no known exploits in the wild at this time.
Mitigation Recommendations
A patch is available that extends the section-name safety checks to option names, rejecting unsafe characters such as '=', '#', ';', '[', ']', and whitespace. Users should upgrade GitPython to a fixed version beyond 3.1.57 and snowflake-cli outside the affected range >=3.4.1 <3.25.0. Until patched, avoid passing untrusted input as option names to the config writer. Review application code that interacts with GitPython's config writer to ensure option names are not attacker-controlled.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-snowflake-cli-CVE-2026-76221
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abb41adf7a7c54106cc3a69
Added to database: 09/29/2026, 04:42:21 UTC
Last enriched: 09/29/2026, 05:01:23 UTC
Last updated: 09/29/2026, 05:01:23 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.