Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.64% | — | Gitpython Project Gitpython | 1/8/2026 | 3/9/2026 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can… | |
| Analizada | Alta (8.6) | 1.3% | — | Gitpython Project Gitpython | 1/8/2026 | 3/9/2026 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for… | |
| Analizada | Alta (8.7) | 0.33% | — | Gitpython Project Gitpython | 1/8/2026 | 3/9/2026 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or… | |
| Analizada | Alta (7.8) | 0.22% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\t), but Git still… | |
| Analizada | Alta (7.8) | 0.44% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory via insufficient… | |
| Modificada | Crítica (9.8) | 0.71% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--branch main --config core.hooksPath=/x" passes validation (starts with --branch), but after split… | |
| Analizada | Alta (8.8) | 0.90% | — | Gitpython Project Gitpython | 7/5/2026 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes… | |
| Modificada | Alta (7.8) | 0.32% | — | Gitpython Project Gitpython | 11/1/2024 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython uses an untrusted search path if it uses a shell to run `git`, as well as when it runs `bash.exe` to interpret hooks. If either of those features are used on Windows, a malicious… | |
| Modificada | Media (6.5) | 1.1% | — | Gitpython Project Gitpython | 30/8/2023 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This… | |
| Modificada | Alta (7.8) | 0.51% | — | Gitpython Project Gitpython | 28/8/2023 | 17/6/2026 | GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program… | |
| Modificada | Crítica (9.8) | 1.2% | — | Gitpython Project Gitpython | 11/8/2023 | 17/6/2026 | GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. | |
| Modificada | Crítica (9.8) | 5.7% | — | Gitpython Project GitpythonFedoraproject FedoraDebian Linux | 6/12/2022 | 17/6/2026 | All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient… |