High severity8.1NVD Advisory· Published Aug 13, 2026
CVE-2026-73620
CVE-2026-73620
Description
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.1.57
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.