Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-78675

GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.2%
CVSS Severity
CVSS v3 Score 8.4
Products affected by CVE-2026-78675


Contact Us

Shodan ® - All rights reserved