---
id: CVE-2026-78679
title: >-
  GitPython before 3.1.59 contains an arbitrary file read vulnerability in
  TagReference.create() where a positional reference parameter bypasses the
  unsafe option guard
summary: >-
  GitPython before 3.1.59 contains an arbitrary file read vulnerability in
  TagReference.create() where a positional reference parameter bypasses the
  unsafe option guard. Attackers can supply a reference value like --file=<path>
  to read arb…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-73
  - CWE-22
  - CWE-88
  - CWE-200
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openstack_platform 16.2
  - satellite 6
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - satellite 6.18
  - satellite 6.19
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - satellite 6.18
  - satellite 6.19
published: '2026-08-25'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:44:42.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78679'
references:
  - url: >-
      https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3wxw-xv34-2frg
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78679.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-78679'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2523205'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-78679'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78679'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59135'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71113'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59136'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71179'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71177'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68764'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68780'
  - url: 'https://github.com/gitpython-developers/GitPython/pull/2208'
  - url: >-
      https://github.com/gitpython-developers/GitPython/commit/1b0d2d9b91575f7db44ef4ff58ac37fc9335e5f6
  - url: 'https://github.com/gitpython-developers/GitPython'
  - url: 'https://github.com/gitpython-developers/GitPython/releases/tag/3.1.59'
  - url: 'https://github.com/advisories/GHSA-3wxw-xv34-2frg'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00255
epssPercentile: 0.15229
aliases:
  - GHSA-3wxw-xv34-2frg
  - PYSEC-2026-3837
ecosystem: pip
ingestedAt: '2026-09-08T20:10:03.214Z'
---

## Overview

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-78679)

Affected packages:

- `gitpython < 3.1.59`

Patched in:

- `gitpython 3.1.59`

Source: https://osv.dev/vulnerability/GHSA-3wxw-xv34-2frg

## Vendor advisories

- **RHSA-2026:59135** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59135)
- **RHSA-2026:71113** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71113)
- **RHSA-2026:59136** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59136)
- **RHSA-2026:71179** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71179)
- **RHSA-2026:71177** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:71177)
- **RHSA-2026:68764** · Red Hat · fixed in: Red Hat Satellite 6.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68764)
- **RHSA-2026:68780** · Red Hat · fixed in: Red Hat Satellite 6.19 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68780)
- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenStack Platform 16.2, … · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-78679.json)
