VulnSea

gitpython vulnerabilities

CVEs whose affected-version data names the gitpython package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

45 CVEsRSS

GHSA-4vpg-pfj8-m33qHigh· 8.4
1mo ago

Duplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

Duplicate Advisory: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

Twilightgitpython · gitpythonvia GHSA
CVE-2026-67326High· 7.0
1mo ago

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] se…

Twilightgitpython_project · gitpythonEPSS 0.28%via NVD
CVE-2026-67323High· 8.4
1mo ago

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

TwilightGitPython · GitPythonEPSS 1.0%via NVD
GHSA-94p4-4cq8-9g67High· 7.5
1mo ago

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

TwilightGitPython · GitPythonvia GHSA
GHSA-fjr4-x663-mwxcHigh· 8.1
1mo ago

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

TwilightGitPython · GitPythonvia GHSA
GHSA-6p8h-3wgx-97gfHigh· 7.5
1mo ago

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

TwilightGitPython · GitPythonvia GHSA
GHSA-r9mr-m37c-5fr3High· 8.8
1mo ago

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

TwilightGitPython · GitPythonvia GHSA
GHSA-3rp5-jjmw-4wv2High· 7.0
1mo ago

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

Twilightgitpython · gitpythonvia GHSA
GHSA-rwj8-pgh3-r573High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

Twilightgitpython · gitpythonvia GHSA
GHSA-956x-8gvw-wg5vHigh· 8.4
2mo ago

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

TwilightGitPython · GitPythonvia GHSA
GHSA-v396-v7q4-x2qjHigh
2mo ago

GitPython unsafe clone option gate bypass through joined short options

GitPython unsafe clone option gate bypass through joined short options

TwilightGitPython · GitPythonvia GHSA
GHSA-2f96-g7mh-g2hxHigh· 8.8
2mo ago

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

TwilightGitPython · GitPythonvia GHSA
CVE-2026-44243High· 7.1
4mo ago

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

Twilightgitpython · gitpythonEPSS 0.42%via OSV
CVE-2024-22190High· 7.8
2y ago

Untrusted search path under some conditions on Windows allows arbitrary code execution

Untrusted search path under some conditions on Windows allows arbitrary code execution

Twilightgitpython · gitpythonEPSS 0.32%via OSV
CVE-2023-40590High· 7.8
3y ago

GitPython untrusted search path on Windows systems leading to arbitrary code execution

GitPython untrusted search path on Windows systems leading to arbitrary code execution

Twilightgitpython · gitpythonEPSS 0.50%via OSV
gitpython vulnerabilities (CVEs) — page 2 · VulnSea