CVE-2026-78678Medium· 6.5▾ SunlitA flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
6.5 → —
medium → none
Last analysed / modified upstream
— → 6.5
none → medium
6.5 → —
medium → none
— → 6.5
none → medium
6.5 → —
medium → none
— → 6.5
none → medium
A flaw was found in GitPython. An incomplete denylist in the unsafe_git_revision_options guard omits --contents and -S options. This allows an attacker to read arbitrary files by passing these options to the Repo.blame() function. This can lead to information disclosure, as attackers can supply revision values like --contents=/etc/passwd to leak file contents.
gitpython: GitPython: Arbitrary file read via Repo.blame() — rated Moderate by Red Hat. Released 2026-08-25, updated 2026-09-09.
Affected:
No fix planned:
Not affected:
Fix deferred
Workarounds / mitigations:
Affected packages:
gitpython < 3.1.59Patched in:
gitpython 3.1.59Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78679Medium· 6.5GitPython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)
CVE-2026-78676Critical· 9.8gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)
CVE-2026-78675Medium· 5.5GitPython: GitPython: Local file content disclosure via malicious .gitmodules (CVE-2026-78675)
CVE-2026-73620High· 8.8gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620)
CVE-2026-67322High· 7.5GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()
CVE-2026-79675High· 8.1nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options (CVE-2026-79675)