VYPR
Vendor

Gitpython Project

Products
1
CVEs
37
Across products
37
Status
Private

Products

1

Recent CVEs

37
View all 37 CVEs →
  • CVE-2026-78676CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after…

  • CVE-2026-67324CriAug 1, 2026
    risk 0.57cvss 9.8epss 0.01

    GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=...,…

  • CVE-2023-40267CriAug 11, 2023
    risk 0.57cvss 9.8epss 0.01

    GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

  • CVE-2026-87817HigSep 9, 2026
    risk 0.50cvss 8.8epss 0.00

    GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked…

  • CVE-2026-76221HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option…

  • CVE-2026-76220HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like…

  • CVE-2026-73625HigAug 13, 2026
    risk 0.50cvss 8.8epss 0.01

    GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push,…

  • CVE-2026-67325HigAug 1, 2026
    risk 0.50cvss 8.8epss 0.02

    GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git…

  • CVE-2026-42215HigMay 7, 2026
    risk 0.50cvss 8.8epss 0.01

    GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass…

  • CVE-2026-78675HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.00

    GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to…

  • CVE-2026-67323HigAug 1, 2026
    risk 0.48cvss 8.4epss 0.01

    GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits()…

  • CVE-2026-76222HigAug 19, 2026
    risk 0.46cvss 8.2epss 0.00

    GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule…

  • CVE-2026-76219HigAug 19, 2026
    risk 0.46cvss 8.1epss 0.01

    GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers…

  • CVE-2026-73624HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.01

    GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to…

  • CVE-2026-73620HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.01

    GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files…

  • CVE-2026-42284HigMay 7, 2026
    risk 0.46cvss 8.1epss 0.01

    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation…

  • CVE-2022-24439HigDec 6, 2022
    risk 0.46cvss 8.1epss 0.06

    All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes…

  • CVE-2026-44244HigMay 7, 2026
    risk 0.44cvss 7.8epss 0.00

    GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines…

  • CVE-2024-22190HigJan 11, 2024
    risk 0.44cvss 7.8epss 0.00

    GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those…

  • CVE-2023-40590HigAug 28, 2023
    risk 0.44cvss 7.8epss 0.01

    GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a…