{"id":"CVE-2026-73624","title":"GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs","summary":"GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter o…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-88"],"vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","affected":["exploit_intelligence","migration_toolkit_for_applications 8","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","satellite 6","satellite_6_19_for_rhel 9","openshift_ai 2.25"],"patched":["satellite_6_19_for_rhel 9","openshift_ai 2.25"],"published":"2026-08-13","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:36:38.867","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73624","references":[{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-x663-mwxc","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-overwrite-via-diff","label":"disclosure@vulncheck.com"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-fjr4-x663-mwxc","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73624.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-73624"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515243"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73624"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73624"},{"url":"https://access.redhat.com/errata/RHSA-2026:63385"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://github.com/gitpython-developers/GitPython/pull/2180"},{"url":"https://github.com/gitpython-developers/GitPython/commit/1d51b891d7f236044a6aa17498ec682b63dad6e6"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/gitpython-developers/GitPython/releases/tag/3.1.54"},{"url":"https://access.redhat.com/errata/RHSA-2026:67279"},{"url":"https://access.redhat.com/errata/RHSA-2026:68764"},{"url":"https://access.redhat.com/errata/RHSA-2026:68771"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"},{"url":"https://access.redhat.com/errata/RHSA-2026:68776"}],"tags":["nvd","csaf","vex","red-hat","osv","pip"],"epss":0.00334,"epssPercentile":0.26941,"aliases":["GHSA-fjr4-x663-mwxc"],"ecosystem":"pip","ingestedAt":"2026-08-14T19:18:45.515Z","slug":"CVE-2026-73624","body":"## Overview\n\nGitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-73624)\n\nAffected packages:\n\n- `gitpython < 3.1.54`\n\nPatched in:\n\n- `gitpython 3.1.54`\n\nSource: https://osv.dev/vulnerability/GHSA-fjr4-x663-mwxc\n\n## Vendor advisories\n\n- **RHSA-2026:63385** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63385)\n- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, Migration Toolkit for Applications 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73624.json)\n- **RHSA-2026:67279** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67279)\n- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)\n- **RHSA-2026:68771** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68771)\n- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)\n- **RHSA-2026:68776** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68776)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}