new file mode 100644
@@ -0,0 +1,37 @@
+From dc3885fd7b4cee9ce4bf04d120e63ea00d905431 Mon Sep 17 00:00:00 2001
+From: "GPT 5.4" <codex@openai.com>
+Date: Tue, 21 Apr 2026 09:30:29 +0800
+Subject: [PATCH] Make sure that multi-options are checked after splitting them
+ with `shlex`
+
+CVE: CVE-2026-42284
+Upstream-Status: Backport [https://github.com/gitpython-developers/GitPython/commit/c9a26789d88b18f8b4620f37307df2976292d2a0]
+
+Backport Changes:
+- Omit regression tests because the Scarthgap PyPI source
+ archive does not include the upstream test suite.
+
+Co-authored-by: Sebastian Thiel <sebastian.thiel@icloud.com>
+(cherry picked from commit c9a26789d88b18f8b4620f37307df2976292d2a0)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ git/repo/base.py | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/git/repo/base.py b/git/repo/base.py
+index f5069dbf..92ace3a0 100644
+--- a/git/repo/base.py
++++ b/git/repo/base.py
+@@ -1271,8 +1271,8 @@ class Repo:
+ Git.check_unsafe_protocols(str(url))
+ if not allow_unsafe_options:
+ Git.check_unsafe_options(options=list(kwargs.keys()), unsafe_options=cls.unsafe_git_clone_options)
+- if not allow_unsafe_options and multi_options:
+- Git.check_unsafe_options(options=multi_options, unsafe_options=cls.unsafe_git_clone_options)
++ if not allow_unsafe_options and multi:
++ Git.check_unsafe_options(options=multi, unsafe_options=cls.unsafe_git_clone_options)
+
+ proc = git.clone(
+ multi,
+--
+2.35.6
@@ -12,6 +12,8 @@ PYPI_PACKAGE = "GitPython"
inherit pypi python_setuptools_build_meta
+SRC_URI += "file://CVE-2026-42284.patch \
+ "
SRC_URI[sha256sum] = "2d99869e0fef71a73cbd242528105af1d6c1b108c60dfabd994bf292f76c3ceb"
DEPENDS += " python3-gitdb"