rpm package
opensuse/python-GitPython&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Leap%2016.0
Vulnerabilities (26)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-87819 | Hig | 7.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Sep 9, 2026 | GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause q | |
| CVE-2026-87818 | Med | 6.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Sep 9, 2026 | GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeat | |
| CVE-2026-87817 | Hig | 8.8 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Sep 9, 2026 | GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hook | |
| CVE-2026-78679 | Med | 6.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 25, 2026 | GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the | |
| CVE-2026-78678 | Med | 6.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 25, 2026 | GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents | |
| CVE-2026-78677 | Hig | 7.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 25, 2026 | GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect reposito | |
| CVE-2026-78676 | Cri | 9.8 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 25, 2026 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after | |
| CVE-2026-78675 | Hig | 8.4 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 25, 2026 | GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sen | |
| CVE-2026-76222 | Hig | 8.2 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 19, 2026 | GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule nam | |
| CVE-2026-76221 | Hig | 8.8 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 19, 2026 | GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option name | |
| CVE-2026-76220 | Hig | 8.8 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 19, 2026 | GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_fro | |
| CVE-2026-76219 | Hig | 8.1 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 19, 2026 | GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers | |
| CVE-2026-76218 | Hig | 7.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 19, 2026 | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are | |
| CVE-2026-76217 | Med | 6.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 19, 2026 | GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with ful | |
| CVE-2026-73625 | Hig | 8.8 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 13, 2026 | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, | |
| CVE-2026-73624 | Hig | 8.1 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 13, 2026 | GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to at | |
| CVE-2026-73623 | Hig | 7.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 13, 2026 | GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout | |
| CVE-2026-73622 | Hig | 7.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 13, 2026 | GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that a | |
| CVE-2026-73621 | Med | 5.4 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 13, 2026 | GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Com | |
| CVE-2026-73620 | Hig | 8.1 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 13, 2026 | GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files retu |
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause q
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeat
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hook
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect reposito
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sen
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule nam
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option name
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_fro
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with ful
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push,
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to at
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that a
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Com
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files retu
Page 1 of 2