From dc3885fd7b4cee9ce4bf04d120e63ea00d905431 Mon Sep 17 00:00:00 2001 From: "GPT 5.4" Date: Tue, 21 Apr 2026 09:30:29 +0800 Subject: [PATCH] Make sure that multi-options are checked after splitting them with `shlex` CVE: CVE-2026-42284 Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0] Backport Changes: - Omit regression tests because the Scarthgap PyPI source archive does not include the upstream test suite. Co-authored-by: Sebastian Thiel (cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0) Signed-off-by: Darsh Kelaiya --- git/repo/base.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/git/repo/base.py b/git/repo/base.py index f5069dbf..92ace3a0 100644 --- a/git/repo/base.py +++ b/git/repo/base.py @@ -1271,8 +1271,8 @@ class Repo: Git.check_unsafe_protocols(str(url)) if not allow_unsafe_options: Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options) - if not allow_unsafe_options and multi_options: - Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options) + if not allow_unsafe_options and multi: + Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options) proc = git.clone( multi, -- 2.35.6