Skip to main content

Snowflake cli: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite (CVE-2026-76219)

0
High
Published: 08/20/2026 (08/20/2026, 09:40:01 UTC)
Source: GCVE Database
Product: snowflake-cli

Description

GitPython's IndexFile methods from_tree, reset, and merge_tree allow an attacker to overwrite arbitrary files by injecting unsafe git read-tree options. These methods append caller-controlled treeish strings to git read-tree without guarding against unsafe options or using a '--' separator. This enables an attacker to specify the --index-output option to write a valid git-index blob to any file path writable by the host process, causing file corruption or destruction. The vulnerability affects GitPython versions >=3.4.1 and <3.25.0 and has a CVSS score of 8.1 (high severity). A patch is available to add unsafe option checks and proper argument separation.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected software

Homebrewmore threats →ghsa
snowflake-cli
pkg:brew/snowflake-cli
Affected versions
>=3.4.1 <3.25.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 05:01:29 UTC

Technical Analysis

The vulnerability (CVE-2026-76219) exists in GitPython's IndexFile.from_tree, reset, and merge_tree methods, which call git read-tree with positional treeish arguments that are influenced by the caller. These methods do not implement any checks for unsafe options nor use a '--' separator before positional arguments. This allows an attacker to inject the '--index-output=<file>' option, which causes git read-tree to write its index output to an arbitrary file path controlled by the attacker. The last occurrence of --index-output wins, enabling overwriting of arbitrary files with a valid git-index blob. This can lead to arbitrary file overwrite or destruction at the privileges of the host process. The vulnerability was not fixed in the commit that guarded other git commands and remains present in GitPython versions up to 3.25.0. The suggested fix is to add a check_unsafe_options guard and/or insert a '--' separator before positional arguments to block unsafe options like --index-output.

Potential Impact

An attacker able to control the treeish argument to these methods can overwrite arbitrary files on the host filesystem with a valid git-index blob. While the content is constrained and does not allow remote code execution, the arbitrary file overwrite can corrupt or destroy important files such as configuration files or other writable files, leading to integrity and availability impacts. The attack executes with the privileges of the host process running the vulnerable code.

Mitigation Recommendations

A patch is available to address this vulnerability by adding a check_unsafe_options guard with an allow_unsafe_options parameter to the affected methods and/or by inserting a '--' separator before positional treeish arguments to block injection of unsafe options like --index-output. Users should apply the official fix from GitPython to versions >=3.4.1 <3.25.0. Until patched, avoid passing untrusted input to these methods.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-snowflake-cli-CVE-2026-76219
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6abb41adf7a7c54106cc3a6a

Added to database: 09/29/2026, 04:42:21 UTC

Last enriched: 09/29/2026, 05:01:29 UTC

Last updated: 09/29/2026, 05:01:29 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses