VYPR

Gitpython

by Gitpython Project

pypi: gitpython

Source repositories

CVEs (36)

  • CVE-2026-87819HigSep 9, 2026
    risk 0.42cvss 7.5epss 0.00

    GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause…

  • CVE-2026-78677HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.00

    GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect…

  • CVE-2026-76218HigAug 19, 2026
    risk 0.42cvss 7.5epss 0.01

    GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are…

  • CVE-2026-73623HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.01

    GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious…

  • CVE-2026-73622HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that…

  • CVE-2026-67322HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who…

  • CVE-2026-69097HigAug 3, 2026
    risk 0.39cvss 7.0epss 0.00

    GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's…

  • CVE-2026-67326HigAug 1, 2026
    risk 0.39cvss 7.0epss 0.00

    GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to…

  • CVE-2026-44243HigMay 7, 2026
    risk 0.39cvss 7.1epss 0.00

    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the…

  • CVE-2026-87818MedSep 9, 2026
    risk 0.35cvss 6.5epss 0.00

    GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle,…

  • CVE-2026-78679MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.00

    GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in…

  • CVE-2026-78678MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.00

    GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like…

  • CVE-2026-76217MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with…

  • CVE-2026-73619MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned…

  • CVE-2026-73621MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to…

  • CVE-2023-41040MedAug 30, 2023
    risk 0.19cvss 4.0epss 0.01

    GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located…

Page 2 of 2