cbcvebase.

Gitpython-Developers Gitpython vulnerabilities

34 known vulnerabilities affecting gitpython-developers/gitpython.

Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH23MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2026-76217P3MEDIUMCVSS 6.5fixed in 3.1.582026-08-19
CVE-2026-76217 [MEDIUM] CWE-73 CVE-2026-76217: GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.
nvd
CVE-2026-44244P3HIGHCVSS 7.8fixed in 3.1.492026-05-07
CVE-2026-44244 [HIGH] CWE-94 CVE-2026-44244: GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitCo GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as
nvd
CVE-2026-78675P3HIGHCVSS 7.8fixed in 3.1.592026-08-25
CVE-2026-78675 [HIGH] CWE-73 CVE-2026-78675: GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises Mis
nvd
CVE-2026-87819P3HIGHCVSS 7.5fixed in 3.1.602026-09-09
CVE-2026-87819 [HIGH] CWE-1333 CVE-2026-87819: GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_ GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per
nvd
CVE-2026-87818P3MEDIUMCVSS 6.5≥ 3.1.59, < 3.1.602026-09-09
CVE-2026-87818 [MEDIUM] CWE-88 CVE-2026-87818: GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attack GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through disting
nvd
CVE-2026-78678P3MEDIUMCVSS 6.5fixed in 3.1.592026-08-25
CVE-2026-78678 [MEDIUM] CWE-88 CVE-2026-78678: GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options g GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to
nvd
CVE-2026-69097P3HIGHCVSS 7.3fixed in 3.1.532026-08-03
CVE-2026-69097 [HIGH] CWE-74 CVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attacke GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code exec
nvd
CVE-2026-73619P3MEDIUMCVSS 6.5fixed in 3.1.572026-08-13
CVE-2026-73619 [MEDIUM] CWE-73 CVE-2026-73619: GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.
nvd
CVE-2023-40590P3HIGHCVSS 7.8fixed in 3.1.412023-08-28
CVE-2023-40590 [HIGH] CWE-426 CVE-2023-40590: GitPython is a python library used to interact with Git repositories. When resolving a program, Pyt GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in
nvd
CVE-2026-78679P3MEDIUMCVSS 6.5fixed in 3.1.592026-08-25
CVE-2026-78679 [MEDIUM] CWE-73 CVE-2026-78679: GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in the annotated tag message.
nvd
CVE-2026-44243P4HIGHCVSS 7.1fixed in 3.1.482026-05-07
CVE-2026-44243 [HIGH] CWE-22 CVE-2026-44243: GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vul GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in refere
nvd
CVE-2026-100689P4MEDIUMCVSS 5.9fixed in 3.1.622026-09-26
CVE-2026-100689 [MEDIUM] CWE-22 CVE-2026-100689: GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file w GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodules. While a prior fix (GHSA-hmq2-w58f-27jc) added Submodule._validated_name() to constrain the `name` field, and GitPython's own containment guard Submodule._to_relative_path() is applied in add() and move(), Submodule.update() d
nvd
CVE-2026-73621P4MEDIUMCVSS 5.4fixed in 3.1.562026-08-13
CVE-2026-73621 [MEDIUM] CWE-88 CVE-2026-73621: GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, w GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied option
nvd
CVE-2023-41040P4MEDIUMCVSS 6.5fixed in 3.1.372023-08-30
CVE-2023-41040 [MEDIUM] CWE-22 CVE-2023-41040: GitPython is a python library used to interact with Git repositories. In order to resolve some git r GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This allows an attacker to make GitPython
nvd
Gitpython-Developers Gitpython vulnerabilities | cvebase