VulnSea

gitpython has 40 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 37 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 27. The median CVSS is 7.8 (high), with 2 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-88 (14) and CWE-73 (9).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
37 prev 1

Products

  • gitpython 40
40
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

gitpython vulnerabilities

CVEs affecting gitpython, newest first. Open any entry for full detail, references, and exploit status.

40 CVEsRSS

GHSA-6p8h-3wgx-97gfHigh· 7.5
2mo ago

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

TwilightGitPython · GitPythonvia GHSA
GHSA-r9mr-m37c-5fr3High· 8.8
2mo ago

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

TwilightGitPython · GitPythonvia GHSA
GHSA-3rp5-jjmw-4wv2High· 7.0
2mo ago

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

Twilightgitpython · gitpythonvia GHSA
GHSA-rwj8-pgh3-r573High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

Twilightgitpython · gitpythonvia GHSA
GHSA-956x-8gvw-wg5vHigh· 8.4
2mo ago

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

TwilightGitPython · GitPythonvia GHSA
GHSA-v396-v7q4-x2qjHigh
2mo ago

GitPython unsafe clone option gate bypass through joined short options

GitPython unsafe clone option gate bypass through joined short options

TwilightGitPython · GitPythonvia GHSA
GHSA-2f96-g7mh-g2hxHigh· 8.8
2mo ago

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

TwilightGitPython · GitPythonvia GHSA
CVE-2026-44243High· 7.1
4mo ago

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

Twilightgitpython · gitpythonEPSS 0.42%via OSV
CVE-2024-22190High· 7.8
2y ago

Untrusted search path under some conditions on Windows allows arbitrary code execution

Untrusted search path under some conditions on Windows allows arbitrary code execution

Twilightgitpython · gitpythonEPSS 0.32%via OSV
CVE-2023-40590High· 7.8
3y ago

GitPython untrusted search path on Windows systems leading to arbitrary code execution

GitPython untrusted search path on Windows systems leading to arbitrary code execution

Twilightgitpython · gitpythonEPSS 0.50%via OSV
gitpython vulnerabilities (CVEs) — page 2 · VulnSea