cbcvebase.
CVE-2026-73621
published 2026-08-13

CVE-2026-73621: GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without…

PriorityP433medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.21%
11.7th percentile
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=, causing 'git rev-list --output=' to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process's privilege level (no content control, 0-byte truncation).

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-24controller-rhel8——
ansible-automation-platform-24hub-rhel8——
ansible-automation-platform-25controller-rhel8——
ansible-automation-platform-25hub-rhel8——
ansible-automation-platform-26controller-rhel9——
ansible-automation-platform-26hub-rhel9——
ansible-automation-platform-27controller-rhel9——
ansible-automation-platform-27hub-rhel9——
exploit-intelligence-tech-previewvulnerability-analysis-rhel9——
gitpython-developersgitpython< 3.1.563.1.56
gitpython_projectgitpython< 3.1.563.1.56
gitpython_projectgitpython——
mtamta-solution-server-rhel9——
pen-drivepen-drive-scanner-rhel9——
rhaiisvllm-cpu-rhel9——
rhaiisvllm-tpu-rhel9——
rhelai3bootc-cuda-rhel9——
rhelai3bootc-gaudi-rhel9——
rhelai3bootc-rocm-rhel9——
rhelai3disk-image-cuda-rhel9——
rhoaiodh-feature-server-rhel9——
rhoaiodh-mlflow-rhel9——
rhoaiodh-pipeline-runtime-datascience-cpu-py312-rhel9——
rhoaiodh-pipeline-runtime-pytorch-cuda-py312-rhel9——
rhoaiodh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9——

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.