Threats Tagged 'ghsa-2f96-g7mh-g2hx'
View all threats tagged with 'ghsa-2f96-g7mh-g2hx'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-2f96-g7mh-g2hx'
Click on any threat for detailed analysis and mitigation recommendations
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist 0 GitPython contains a command injection vulnerability due to incomplete blocking of unsafe git options. The fix for CVE-2026-42215 implemented a blocklist for dangerous git options but did not account for git's acceptance of unambiguous long-option prefix abbreviations. This allows attackers to bypass the blocklist by using abbreviated option keys, leading to command injection when GitPython emits these options to git commands. The vulnerability affects all versions carrying the 3.1.47 blocklist fix through versions before 3.1.51. Exploitation requires a host application that passes attacker-controlled keyword argument keys to GitPython's clone, fetch, pull, or push methods. The severity is high, reflecting potential remote code execution impact. Join the discussion | GCVE Database | 07/21/2026, 19:43:43 UTC Added: 07/22/2026, 00:11:47 UTC |
Showing 1 to 1 of 1 result