GHSA-2pxq-5vcg-rq29High· 8.8▾ TwilightDuplicate Advisory: Repository content can impersonate the git directory, leading to arbitrary code execution
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-239g-whfq-7xj9. This link is maintained to preserve external references.
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim calls index.commit() on a cloned or opened repository.
gitpython <= 3.1.59Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87817High· 8.8GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD
GHSA-9rj7-rf2p-w77rHigh· 7.5GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
GHSA-59cr-6r3x-644wMediumGitPython submodule update path traversal can write outside the repository
GHSA-qpf5-3wfw-fh7qHigh· 7.5Duplicate Advisory: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
GHSA-whh4-5q6c-9v3xMedium· 6.5GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
CVE-2023-40590High· 7.8GitPython untrusted search path on Windows systems leading to arbitrary code execution