Files
WSL/tools
Ben Hillis 6a462fb2a1 Bump GitPython to 3.1.50 to address CVE-2026-42215 bypass (#40504)
Fixes Dependabot alerts #22 and #23. GitPython <= 3.1.49 has a newline injection vulnerability in config_writer() section parameter that bypasses the CVE-2026-42215 patch and enables RCE via core.hooksPath.

Co-authored-by: Ben Hillis <benhill@ntdev.microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-12 01:30:34 +00:00
..