CVE-2026-78675
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
25/08/2026
Last modified:
25/08/2026
Description
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.40
Severity 3.x
HIGH



