VYPR

rpm package

opensuse/python-GitPython&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Leap%2016.0

Vulnerabilities (26)

  • CVE-2026-73619MedAug 13, 2026
    affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1

    GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned

  • CVE-2026-69097HigAug 3, 2026
    affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1

    GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config

  • CVE-2026-67326HigAug 1, 2026
    affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1

    GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-c

  • CVE-2026-67325HigAug 1, 2026
    affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1

    GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso

  • CVE-2026-67323HigAug 1, 2026
    affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1

    GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits()

  • CVE-2026-67322HigAug 1, 2026
    affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1

    GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who contr

Page 2 of 2