Medium severity6.5NVD Advisory· Published Aug 25, 2026· Updated Sep 24, 2026
CVE-2026-78679
CVE-2026-78679
Description
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
GitPythonPyPI | < 3.1.59 | 3.1.59 |
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Tumbleweed
< 3.1.44-160000.4.1+ 1 more
- (no CPE)range: < 3.1.44-160000.4.1
- (no CPE)range: < 3.1.59-3.1
- Range: <3.1.59
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-3wxw-xv34-2frgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-78679ghsaADVISORY
- github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6ghsaWEB
- github.com/gitpython-developers/GitPython/pull/2208ghsaWEB
- github.com/gitpython-developers/GitPython/releases/tag/3.1.59ghsaWEB
- github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frgnvdWEB
- www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-createnvdWEB
News mentions
1- Gitpython: Five Vulnerabilities Including Critical Flaw Disclosed TogetherVypr Intelligence · Aug 25, 2026