Gitpython Project
Gitpython Project Gitpython: vulnerabilidades y CVE
Gitpython Project Gitpython tiene 35 vulnerabilidades publicadas, 30 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses30
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87819 | Alta (8.7) | 0.52% | — | 9 sept 2026 | GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed… |
| CVE-2026-87818 | Alta (7.1) | 0.41% | — | 9 sept 2026 | GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with… |
| CVE-2026-87817 | Alta (8.7) | 0.40% | — | 9 sept 2026 | GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary… |
| CVE-2026-78678 | Alta (7.1) | 0.41% | — | 25 ago 2026 | GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to… |
| CVE-2026-78677 | Alta (8.7) | 0.65% | — | 25 ago 2026 | GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir… |
| CVE-2026-78676 | Crítica (9.3) | 0.78% | — | 25 ago 2026 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files… |
| CVE-2026-78675 | Alta (8.6) | 0.18% | — | 25 ago 2026 | GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a… |
| CVE-2026-76222 | Alta (8.4) | 0.42% | — | 19 ago 2026 | GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft… |
| CVE-2026-76221 | Alta (8.7) | 0.77% | — | 19 ago 2026 | GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace… |
| CVE-2026-76220 | Alta (8.7) | 0.91% | — | 19 ago 2026 | GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply… |
| CVE-2026-76219 | Alta (7.2) | 0.54% | — | 19 ago 2026 | GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree… |
| CVE-2026-76218 | Alta (7.7) | 0.83% | — | 19 ago 2026 | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious… |
| CVE-2026-76217 | Alta (7.1) | 0.41% | — | 19 ago 2026 | GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul… |
| CVE-2026-73625 | Alta (8.7) | 0.92% | — | 13 ago 2026 | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply… |
| CVE-2026-73624 | Alta (7.2) | 0.55% | — | 13 ago 2026 | GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the… |
| CVE-2026-73623 | Alta (7.7) | 0.83% | — | 13 ago 2026 | GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply… |
| CVE-2026-73622 | Alta (8.7) | 0.51% | — | 13 ago 2026 | GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references.… |
| CVE-2026-73621 | Media (5.3) | 0.36% | — | 13 ago 2026 | GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling… |
| CVE-2026-73620 | Alta (7.2) | 0.57% | — | 13 ago 2026 | GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary… |
| CVE-2026-73619 | Alta (7.1) | 0.41% | — | 13 ago 2026 | GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read… |
| CVE-2026-69097 | Alta (7.3) | 0.27% | — | 3 ago 2026 | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand… |
| CVE-2026-67326 | Alta (7.3) | 0.25% | — | 1 ago 2026 | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create… |
| CVE-2026-67325 | Alta (8.7) | 2.2% | — | 1 ago 2026 | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated… |
| CVE-2026-67324 | Crítica (9.3) | 0.64% | — | 1 ago 2026 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced… |
| CVE-2026-67323 | Alta (8.6) | 1.3% | — | 1 ago 2026 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to… |
| CVE-2026-67322 | Alta (8.7) | 0.33% | — | 1 ago 2026 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls… |
| CVE-2026-44244 | Alta (7.8) | 0.22% | — | 7 may 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write()… |
| CVE-2026-44243 | Alta (7.8) | 0.44% | — | 7 may 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to… |
| CVE-2026-42284 | Crítica (9.8) | 0.71% | — | 7 may 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like… |
| CVE-2026-42215 | Alta (8.8) | 0.90% | — | 7 may 2026 | GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the… |