{"id":"CVE-2026-78678","title":"gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)","summary":"A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cvssSource":"vendor","cwe":["CWE-88","CWE-200"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","migration_toolkit_for_applications 8","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openstack_platform 16.2","openstack_platform 17.1","satellite 6"],"patched":["gitpython 3.1.59"],"published":"2026-08-25","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:11:12+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78678.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78678.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-78678"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523196"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78678"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78678"},{"url":"https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-5xxx-qhh7-9287"},{"url":"https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame"},{"url":"https://github.com/gitpython-developers/GitPython"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/gitpython/PYSEC-2026-3788.yaml"},{"url":"https://github.com/advisories/GHSA-5xxx-qhh7-9287"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.0024,"epssPercentile":0.1539,"aliases":["GHSA-5xxx-qhh7-9287","PYSEC-2026-3788"],"ecosystem":"pip","ingestedAt":"2026-09-03T19:32:11.839Z","slug":"CVE-2026-78678","body":"## Overview\n\nA flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. This can lead to information disclosure, as attackers can supply revision values like `--contents=/etc/passwd` to leak file contents.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78678.json)\n\n**gitpython: GitPython: Arbitrary file read via Repo.blame()** — rated Moderate by Red Hat. Released 2026-08-25, updated 2026-09-09.\n\nAffected:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat Satellite 6\n\nNo fix planned:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2\n- Red Hat Hardened Images\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-78678)\n\nAffected packages:\n\n- `gitpython < 3.1.59`\n\nPatched in:\n\n- `gitpython 3.1.59`\n\nSource: https://osv.dev/vulnerability/GHSA-5xxx-qhh7-9287","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":8217,"id":"CVE-2026-78678","ts":1788919993255,"field":"cvss","old":null,"new":"6.5"},{"seq":8216,"id":"CVE-2026-78678","ts":1788919993255,"field":"severity","old":"none","new":"medium"},{"seq":8026,"id":"CVE-2026-78678","ts":1788919280609,"field":"cvss","old":"6.5","new":null},{"seq":8025,"id":"CVE-2026-78678","ts":1788919280609,"field":"severity","old":"medium","new":"none"},{"seq":7835,"id":"CVE-2026-78678","ts":1788916353760,"field":"cvss","old":null,"new":"6.5"},{"seq":7834,"id":"CVE-2026-78678","ts":1788916353760,"field":"severity","old":"none","new":"medium"},{"seq":7644,"id":"CVE-2026-78678","ts":1788915297313,"field":"cvss","old":"6.5","new":null},{"seq":7643,"id":"CVE-2026-78678","ts":1788915297313,"field":"severity","old":"medium","new":"none"},{"seq":7453,"id":"CVE-2026-78678","ts":1788912713343,"field":"cvss","old":null,"new":"6.5"},{"seq":7452,"id":"CVE-2026-78678","ts":1788912713343,"field":"severity","old":"none","new":"medium"},{"seq":7262,"id":"CVE-2026-78678","ts":1788911331245,"field":"cvss","old":"6.5","new":null},{"seq":7261,"id":"CVE-2026-78678","ts":1788911331245,"field":"severity","old":"medium","new":"none"},{"seq":7066,"id":"CVE-2026-78678","ts":1788909076584,"field":"cvss","old":null,"new":"6.5"},{"seq":7065,"id":"CVE-2026-78678","ts":1788909076584,"field":"severity","old":"none","new":"medium"},{"seq":6878,"id":"CVE-2026-78678","ts":1788907391356,"field":"cvss","old":"6.5","new":null},{"seq":6877,"id":"CVE-2026-78678","ts":1788907391356,"field":"severity","old":"medium","new":"none"},{"seq":6680,"id":"CVE-2026-78678","ts":1788905442914,"field":"cvss","old":null,"new":"6.5"},{"seq":6679,"id":"CVE-2026-78678","ts":1788905442914,"field":"severity","old":"none","new":"medium"},{"seq":6498,"id":"CVE-2026-78678","ts":1788903459568,"field":"cvss","old":"6.5","new":null},{"seq":6497,"id":"CVE-2026-78678","ts":1788903459568,"field":"severity","old":"medium","new":"none"},{"seq":6288,"id":"CVE-2026-78678","ts":1788901809887,"field":"cvss","old":null,"new":"6.5"},{"seq":6287,"id":"CVE-2026-78678","ts":1788901809887,"field":"severity","old":"none","new":"medium"},{"seq":6118,"id":"CVE-2026-78678","ts":1788899561987,"field":"cvss","old":"6.5","new":null},{"seq":6117,"id":"CVE-2026-78678","ts":1788899561987,"field":"severity","old":"medium","new":"none"},{"seq":5921,"id":"CVE-2026-78678","ts":1788898179164,"field":"cvss","old":null,"new":"6.5"},{"seq":5920,"id":"CVE-2026-78678","ts":1788898179164,"field":"severity","old":"none","new":"medium"},{"seq":5810,"id":"CVE-2026-78678","ts":1788895711048,"field":"cvss","old":"6.5","new":null},{"seq":5809,"id":"CVE-2026-78678","ts":1788895711048,"field":"severity","old":"medium","new":"none"},{"seq":5720,"id":"CVE-2026-78678","ts":1788894572479,"field":"cvss","old":null,"new":"6.5"},{"seq":5719,"id":"CVE-2026-78678","ts":1788894572479,"field":"severity","old":"none","new":"medium"}]}