CVE-2026-78679
published 2026-08-25CVE-2026-78679: GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.24%
15.6th percentile
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-24 | controller-rhel8 | — | — |
| ansible-automation-platform-24 | hub-rhel8 | — | — |
| ansible-automation-platform-25 | controller-rhel8 | — | — |
| ansible-automation-platform-25 | hub-rhel8 | — | — |
| ansible-automation-platform-26 | controller-rhel9 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-27 | controller-rhel9 | — | — |
| ansible-automation-platform-27 | hub-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| exploit-intelligence | vulnerability-analysis-rhel9 | — | — |
| gitpython-developers | gitpython | < 3.1.59 | 3.1.59 |
| gitpython_project | gitpython | — | — |
| gitpython_project | gitpython | >= 0 < 3.1.59 | 3.1.59 |
| mta | mta-solution-server-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
| rhelai3 | disk-image-cuda-rhel9 | — | — |
| rhoai | odh-feature-server-rhel9 | — | — |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa8.8HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
ghsa·2026-09-08·CVSS 8.8
CVE-2026-78679 [HIGH] CWE-88 GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix bypass of commit `3af0c251` (the fix for GHSA-3f7w-8rr8-f37f's tag instance).
## Root Cause
The fix `3af0c251` added `unsafe_git_tag_options = ["--file","-F"]` and a guard call, but the guard is `Git.check_unsafe_options(options=Git._option_candidates([], kwargs), unsafe_options=...)` at `git/refs/tag.py:139` — it passes an EMPTY args list and inspects
GHSA
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard.
ghsa_unreviewed·2026-08-25
CVE-2026-78679 [HIGH] CWE-73 GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard.
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
Red Hat
GitPython: GitPython: Arbitrary file read via TagReference.create()
vendor_redhat·2026-08-25·CVSS 6.5
CVE-2026-78679 [MEDIUM] CWE-22 GitPython: GitPython: Arbitrary file read via TagReference.create()
GitPython: GitPython: Arbitrary file read via TagReference.create()
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
A flaw was found in GitPython. A remote attacker with low privileges can exploit a vulnerability in the `TagReference.create()` function, where a positional reference parameter bypasses a security guard. This allows the attacker to supply a specially crafted reference value, such as `--file=`, to read arbitrary files on the system. The contents of these files are then returned within the annotated tag message, leading to informa
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create() [fedora-all]
bugzilla·2026-09-10·CVSS 6.5
CVE-2026-78679 [MEDIUM] CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create() [fedora-all]
CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
Discussion:
This is fixed in 3.1.59, and GitPython is at a later version in all Fedora and EPEL branches, except for EPEL8, which cannot be updated. It’s a real waste of time hav
Bugzilla
CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create() [epel-all]
bugzilla·2026-09-10·CVSS 6.5
CVE-2026-78679 [MEDIUM] CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create() [epel-all]
CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create() [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
Discussion:
This is fixed in 3.1.59, and GitPython is at a later version in all Fedora and EPEL branches, except for EPEL8, which cannot be updated. It’s a real waste of time havin
Bugzilla
CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create()
bugzilla·2026-08-25·CVSS 6.5
CVE-2026-78679 [MEDIUM] CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create()
CVE-2026-78679 GitPython: GitPython: Arbitrary file read via TagReference.create()
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
2026-08-25
Published