VulnSea

GitPython vulnerabilities

CVEs whose affected-version data names the GitPython package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

45 CVEsRSS

CVE-2026-87818Medium· 6.5PoC
1w ago

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create…

Twilightgitpython_project · gitpythonEPSS 0.24%via NVD
CVE-2026-87817High· 8.8
1w ago

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…

Twilightgitpython_project · gitpythonEPSS 0.33%via NVD
CVE-2026-87819High· 7.5
1w ago

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containi…

Twilightgitpython_project · gitpythonEPSS 0.29%via NVD
CVE-2026-78677High· 7.5
1w ago

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside …

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

Twilightgitpython · gitpythonEPSS 0.43%via OSV
GHSA-6rj2-96f5-chj9High· 6.5
3w ago

Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

TwilightGitPython · GitPythonvia GHSA
GHSA-crmc-f4m7-33fjHigh· 8.4
3w ago

Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

Twilightgitpython · gitpythonvia GHSA
GHSA-9557-234j-7rv9Critical· 9.8
3w ago

Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

MidnightGitPython · GitPythonvia GHSA
GHSA-89ff-m8wv-p99rHigh· 6.5
3w ago

Duplicate Advisory: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

Duplicate Advisory: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

Twilightgitpython · gitpythonvia GHSA
GHSA-7r39-6q8m-qw68High· 7.5
3w ago

Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

Twilightgitpython · gitpythonvia GHSA
GHSA-w672-239g-c3grHigh· 6.5
1mo ago

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

Twilightgitpython · gitpythonvia GHSA
GHSA-wv46-xpj8-pw53High· 8.8
1mo ago

Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

Twilightgitpython · gitpythonvia GHSA
GHSA-7jx3-jqcp-hhgcHigh· 8.1
1mo ago

Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

Twilightgitpython · gitpythonvia GHSA
GHSA-3vrx-526r-64rmHigh· 8.2
1mo ago

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

Twilightgitpython · gitpythonvia GHSA
GHSA-298h-jpq4-m665High· 7.5
1mo ago

Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

TwilightGitPython · GitPythonvia GHSA
CVE-2026-76217Medium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

Sunlitgitpython · gitpythonEPSS 0.36%via OSV
GHSA-4gmw-gg2m-w46pHigh· 8.1
1mo ago

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

TwilightGitPython · GitPythonvia GHSA
GHSA-9rj7-rf2p-w77rHigh· 7.5
1mo ago

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

TwilightGitPython · GitPythonvia GHSA
GHSA-hh9p-6wh2-4mfcMedium· 6.5
1mo ago

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

SunlitGitPython · GitPythonvia GHSA
GHSA-hmq2-w58f-27jcHigh· 8.2
1mo ago

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

TwilightGitPython · GitPythonvia GHSA
GHSA-jm78-9fvv-mhgrHigh· 8.8
1mo ago

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

TwilightGitPython · GitPythonvia GHSA
GHSA-wvpp-8hx9-p66jHigh· 8.8
1mo ago

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

TwilightGitPython · GitPythonvia GHSA
CVE-2026-73621Medium· 5.4
1mo ago

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

Sunlitgitpython · gitpythonEPSS 0.21%via OSV
CVE-2026-73619Medium· 6.5
1mo ago

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.ar…

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

Sunlitgitpython · gitpythonEPSS 0.29%via OSV
CVE-2026-69097High· 7.0
1mo ago

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerou…

Twilightgitpython_project · gitpythonEPSS 0.26%via NVD
GHSA-3f7w-8rr8-f37fHigh· 8.1
1mo ago

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

TwilightGitPython · GitPythonvia GHSA
GHSA-539m-9xh6-q6rrMedium· 6.5
1mo ago

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

SunlitGitPython · GitPythonvia GHSA
GHSA-p538-c434-8v24Medium· 5.4
1mo ago

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

SunlitGitPython · GitPythonvia GHSA
GHSA-6r2r-ww24-7h52High· 8.8
1mo ago

Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

Duplicate Advisory: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

Twilightgitpython · gitpythonvia GHSA
GHSA-m4f3-g4cq-hqrxHigh· 7.5
1mo ago

Duplicate Advisory: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

Duplicate Advisory: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

Twilightgitpython · gitpythonvia GHSA
GHSA-cw2r-r7mw-j3hcCritical· 9.8
1mo ago

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

Duplicate Advisory: GitPython unsafe clone option gate bypass through joined short options

Midnightgitpython · gitpythonvia GHSA
GitPython vulnerabilities (CVEs) · VulnSea