cbcvebase.

Gitpython Project Gitpython vulnerabilities

37 known vulnerabilities affecting gitpython_project/gitpython.

Total CVEs
37
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH26MEDIUM6

Vulnerabilities

Page 2 of 2
CVE-2026-76222P3HIGHCVSS 8.2fixed in 3.1.582026-08-19
CVE-2026-76222 [HIGH] CWE-22 CVE-2026-76222: GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating atta
nvd
CVE-2023-40267P3CRITICALCVSS 9.8fixed in 3.1.322023-08-11
CVE-2023-40267 [CRITICAL] CVE-2023-40267: GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: thi GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
ghsanvdosv
CVE-2026-67326P3HIGHCVSS 7.8fixed in 3.1.502026-08-01
CVE-2026-67326 [HIGH] CWE-20 CVE-2026-67326: GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writ GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are
nvd
CVE-2026-76217P3MEDIUMCVSS 6.5fixed in 3.1.582026-08-19
CVE-2026-76217 [MEDIUM] CWE-73 CVE-2026-76217: GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr.
nvd
CVE-2026-44244P3HIGHCVSS 7.8fixed in 3.1.492026-05-07
CVE-2026-44244 [HIGH] CWE-94 CVE-2026-44244: GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitCo GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still accepts an indented [core] stanza as
ghsanvd
CVE-2026-78675P3HIGHCVSS 7.8fixed in 3.1.592026-08-25
CVE-2026-78675 [HIGH] CWE-73 CVE-2026-78675: GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises Mis
ghsanvd
CVE-2026-87819P3HIGHCVSS 7.5fixed in 3.1.602026-09-09
CVE-2026-87819 [HIGH] CWE-1333 CVE-2026-87819: GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_ GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU resources for over two minutes per
ghsanvd
CVE-2026-87818P3MEDIUMCVSS 6.5fixed in 3.1.602026-09-09
CVE-2026-87818 [MEDIUM] CWE-88 CVE-2026-87818: GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attack GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover single-line secrets through disting
ghsanvd
CVE-2026-78678P3MEDIUMCVSS 6.5fixed in 3.1.592026-08-25
CVE-2026-78678 [MEDIUM] CWE-88 CVE-2026-78678: GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options g GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents through the blame result returned to
ghsanvd
CVE-2026-69097P3HIGHCVSS 7.3fixed in 3.1.532026-08-03
CVE-2026-69097 [HIGH] CWE-74 CVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attacke GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code exec
nvd
CVE-2026-73619P3MEDIUMCVSS 6.5fixed in 3.1.572026-08-13
CVE-2026-73619 [MEDIUM] CWE-73 CVE-2026-73619: GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.
nvd
CVE-2026-78679P3HIGHCVSS 8.8≥ 0, < 3.1.592026-09-08
CVE-2026-78679 [HIGH] CWE-88 GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) ## Summary `TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an
ghsa
CVE-2023-40590P3HIGHCVSS 7.8≤ 3.1.322023-08-28
CVE-2023-40590 [HIGH] CWE-426 CVE-2023-40590: GitPython is a python library used to interact with Git repositories. When resolving a program, Pyt GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in
ghsanvdosv
CVE-2024-22190P3HIGHCVSS 7.8fixed in 3.1.412024-01-11
CVE-2024-22190 [HIGH] CVE-2024-22190: GitPython is a python library used to interact with Git repositories. There is an incomplete fix for GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious `git.exe` or `bash.exe` may be run from an
ghsanvdosv
CVE-2026-44243P4HIGHCVSS 7.1fixed in 3.1.482026-05-07
CVE-2026-44243 [HIGH] CWE-22 CVE-2026-44243: GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vul GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient validation of reference paths in refere
ghsanvd
CVE-2026-73621P4MEDIUMCVSS 5.4fixed in 3.1.562026-08-13
CVE-2026-73621 [MEDIUM] CWE-88 CVE-2026-73621: GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, w GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied option
nvd
CVE-2023-41040P4MEDIUMCVSS 6.5≤ 3.1.342023-08-30
CVE-2023-41040 [MEDIUM] CWE-22 CVE-2023-41040: GitPython is a python library used to interact with Git repositories. In order to resolve some git r GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This allows an attacker to make GitPython
ghsanvdosv
Gitpython Project Gitpython vulnerabilities | cvebase