rpm package
opensuse/python-GitPython&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Leap%2016.0
Vulnerabilities (26)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-73619 | Med | 6.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 13, 2026 | GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned | |
| CVE-2026-69097 | Hig | 7.0 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 3, 2026 | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config | |
| CVE-2026-67326 | Hig | 7.0 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 1, 2026 | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-c | |
| CVE-2026-67325 | Hig | 8.8 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 1, 2026 | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso | |
| CVE-2026-67323 | Hig | 8.4 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 1, 2026 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() | |
| CVE-2026-67322 | Hig | 7.5 | < 3.1.44-160000.4.1 | 3.1.44-160000.4.1 | Aug 1, 2026 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who contr |
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-c
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits()
- affected < 3.1.44-160000.4.1fixed 3.1.44-160000.4.1
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who contr
Page 2 of 2