cbcvebase.

Gitpython Project Gitpython vulnerabilities

37 known vulnerabilities affecting gitpython_project/gitpython.

Total CVEs
37
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH26MEDIUM6

Vulnerabilities

Page 1 of 2
CVE-2018-11235P2HIGHCVSS 7.8PoC≥ 0, < 3.1.582026-08-07
CVE-2018-11235 [HIGH] CWE-22 GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython ### Summary GitPython computes the on-disk location of a submodule's separate Git directory (`.git/modules/`) from the submodule's `.gitmodules` section name with no validation. Because that name is fully attacker-cont
ghsa
CVE-2026-73625P2HIGHCVSS 8.8fixed in 3.1.542026-08-13
CVE-2026-73625 [HIGH] CWE-78 CVE-2026-73625: GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_o GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to clone_from, fetch, pull, push, ls_remote, iter_commits, blame, or archive methods to execute arbitrary OS
nvd
CVE-2022-24439P2CRITICALCVSS 9.8fixed in 3.1.302022-12-06
CVE-2022-24439 [CRITICAL] CWE-20 CVE-2022-24439: All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments
ghsanvdosv
CVE-2026-67325P2HIGHCVSS 8.8fixed in 3.1.512026-08-01
CVE-2026-67325 [HIGH] CWE-78 CVE-2026-67325: GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
nvd
CVE-2026-76218P2HIGHCVSS 8.8fixed in 3.1.582026-08-19
CVE-2026-76218 [HIGH] CWE-88 CVE-2026-76218: GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards un GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
nvd
CVE-2026-76220P2HIGHCVSS 8.8fixed in 3.1.582026-08-19
CVE-2026-76220 [HIGH] CWE-88 CVE-2026-76220: GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_from to emit a joined token parsed as --upload-pack, enabling arbitrary OS co
nvd
CVE-2026-42215P2HIGHCVSS 8.8≥ 3.1.30, < 3.1.472026-05-07
CVE-2026-42215 [HIGH] CWE-78 CVE-2026-42215: GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clon
ghsanvd
CVE-2026-73623P2HIGHCVSS 8.8fixed in 3.1.542026-08-13
CVE-2026-73623 [HIGH] CWE-78 CVE-2026-73623: GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --tem GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious post-checkout hooks that execute when git clones the repository.
nvd
CVE-2026-78676P3CRITICALCVSS 9.8fixed in 3.1.592026-08-25
CVE-2026-78676 [CRITICAL] CWE-88 CVE-2026-78676: GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write opera GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code executio
ghsanvd
CVE-2026-67324P2CRITICALCVSS 9.8fixed in 3.1.502026-08-01
CVE-2026-67324 [CRITICAL] CWE-78 CVE-2026-67324: GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of - GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u to bypass the gate that blocks --u
nvd
CVE-2026-76221P3HIGHCVSS 8.8fixed in 3.1.582026-08-19
CVE-2026-76221 [HIGH] CWE-74 CVE-2026-76221: GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #' to execute arbitrary commands via co
nvd
CVE-2026-42284P3CRITICALCVSS 9.8fixed in 3.1.472026-05-07
CVE-2026-42284 [CRITICAL] CWE-88 CVE-2026-42284: GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clon GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split becomes ["--branch", "main", "--c
ghsanvd
CVE-2026-87817P3HIGHCVSS 8.8fixed in 3.1.602026-09-09
CVE-2026-87817 [HIGH] CWE-94 CVE-2026-87817: GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned o
ghsanvd
CVE-2026-67323P3HIGHCVSS 8.4fixed in 3.1.512026-08-01
CVE-2026-67323 [HIGH] CWE-77 CVE-2026-67323: GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a rev
nvd
CVE-2026-73624P3HIGHCVSS 8.1fixed in 3.1.542026-08-13
CVE-2026-73624 [HIGH] CWE-88 CVE-2026-73624: GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.d GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.
nvd
CVE-2026-73620P3HIGHCVSS 8.1fixed in 3.1.572026-08-13
CVE-2026-73620 [HIGH] CWE-22 CVE-2026-73620: GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReferenc GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -F to read arbitrary files returned in-band.
nvd
CVE-2026-76219P3HIGHCVSS 8.1fixed in 3.1.582026-08-19
CVE-2026-76219 [HIGH] CWE-88 CVE-2026-76219: GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a v
nvd
CVE-2026-78677P3HIGHCVSS 7.5fixed in 3.1.592026-08-25
CVE-2026-78677 [HIGH] CWE-22 CVE-2026-78677: GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers t GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary
ghsanvd
CVE-2026-73622P3HIGHCVSS 7.5fixed in 3.1.552026-08-13
CVE-2026-73622 [HIGH] CWE-200 CVE-2026-73622: GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submo GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with environment variable tokens that are expanded into .git/config and .gitmodules, then transmitted to attacke
nvd
CVE-2026-67322P3HIGHCVSS 7.5fixed in 3.1.522026-08-01
CVE-2026-67322 [HIGH] CWE-200 CVE-2026-67322: GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to
nvd
Gitpython Project Gitpython vulnerabilities | cvebase