VulnSea

gitpython_project has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.0 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
Last 90 days
5 prev 0

Products

  • gitpython 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

gitpython_project vulnerabilities

CVEs affecting gitpython_project, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-87818Medium· 6.5PoC
1w ago

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands

GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create…

Twilightgitpython_project · gitpythonEPSS 0.24%via NVD
CVE-2026-87817High· 8.8
1w ago

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…

Twilightgitpython_project · gitpythonEPSS 0.33%via NVD
CVE-2026-87819High· 7.5
1w ago

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containi…

Twilightgitpython_project · gitpythonEPSS 0.29%via NVD
CVE-2026-69097High· 7.0
1mo ago

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerou…

Twilightgitpython_project · gitpythonEPSS 0.26%via NVD
CVE-2026-67326High· 7.0
1mo ago

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] se…

Twilightgitpython_project · gitpythonEPSS 0.28%via NVD
gitpython_project vulnerabilities (CVEs) · VulnSea