Skip to content

[foreman-3.18] Fix CVE-2026-78676: bump GitPython to 3.1.62 - #2498

Merged
brantleyr merged 1 commit into
foreman-3.18from
fix/CVE-2026-78676-gitpython-6.19
Sep 10, 2026
Merged

brantleyr merged 1 commit into
foreman-3.18from
fix/CVE-2026-78676-gitpython-6.19

Conversation

@brantleyr

Copy link
Copy Markdown
Contributor

Resolves CVE-2026-78676 (GitPython Remote Code Execution via config injection, fixed upstream in 3.1.59) by bumping GitPython to 3.1.62.

Bumps GitPython to 3.1.62 to resolve:
- CVE-2026-78676: Remote Code Execution via config injection (fixed in 3.1.59)
@brantleyr brantleyr changed the title Fix CVE-2026-78676: bump GitPython to 3.1.62 [foreman-3.18] Fix CVE-2026-78676: bump GitPython to 3.1.62 Sep 9, 2026
@brantleyr
brantleyr merged commit 7c1e383 into foreman-3.18 Sep 10, 2026
6 of 7 checks passed
@brantleyr
brantleyr deleted the fix/CVE-2026-78676-gitpython-6.19 branch September 10, 2026 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants