VYPR

rpm package

opensuse/python-GitPython&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/python-GitPython&distro=openSUSE%20Tumbleweed

Vulnerabilities (23)

  • CVE-2026-78679MedAug 25, 2026
    affected < 3.1.59-3.1fixed 3.1.59-3.1

    GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the

  • CVE-2026-78678MedAug 25, 2026
    affected < 3.1.59-3.1fixed 3.1.59-3.1

    GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents

  • CVE-2026-78676CriAug 25, 2026
    affected < 3.1.59-3.1fixed 3.1.59-3.1

    GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after

  • CVE-2026-76222HigAug 19, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule nam

  • CVE-2026-76221HigAug 19, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option name

  • CVE-2026-76219HigAug 19, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers

  • CVE-2026-76217MedAug 19, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with ful

  • CVE-2026-73624HigAug 13, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to at

  • CVE-2026-73623HigAug 13, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout

  • CVE-2026-73621MedAug 13, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Com

  • CVE-2026-73620HigAug 13, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files retu

  • CVE-2026-73619MedAug 13, 2026
    affected < 3.1.59-2.1fixed 3.1.59-2.1

    GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned

  • CVE-2026-69097HigAug 3, 2026
    affected < 3.1.58-1.1fixed 3.1.58-1.1

    GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config

  • CVE-2026-67326HigAug 1, 2026
    affected < 3.1.58-1.1fixed 3.1.58-1.1

    GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-c

  • CVE-2026-67325HigAug 1, 2026
    affected < 3.1.58-1.1fixed 3.1.58-1.1

    GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git reso

  • CVE-2026-67322HigAug 1, 2026
    affected < 3.1.58-1.1fixed 3.1.58-1.1

    GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who contr

  • CVE-2026-44244HigMay 7, 2026
    affected < 3.1.49-1.1fixed 3.1.49-1.1

    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines

  • CVE-2026-44243HigMay 7, 2026
    affected < 3.1.49-1.1fixed 3.1.49-1.1

    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository

  • CVE-2026-42215HigMay 7, 2026
    affected < 3.1.49-1.1fixed 3.1.49-1.1

    GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass tha

  • CVE-2023-41040MedAug 30, 2023
    affected < 3.1.56-1.1fixed 3.1.56-1.1

    GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located

Page 1 of 2