Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
3658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.21% | — | Gitlab | 26/8/2026 | 31/8/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due… | |
| Analizada | Media (6.5) | 0.41% | — | Gitlab | 26/8/2026 | 31/8/2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have caused denial of service, due to an unbounded loop triggered by specially crafted input in the SCIM user provisioning… | |
| Aplazada | Baja (2.1) | 0.26% | — | Github CLIAI | 25/8/2026 | 9/9/2026 | GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all available network interfaces by default. While port forwarding is active, a service in a Codespace can therefore become reachable through the user's non-loopback… | |
| Aplazada | Alta (8.4) | 0.27% | — | Git-scm GITAISonirico Mcp-shellAI | 25/8/2026 | 9/9/2026 | mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A caller of the… | |
| Analizada | Alta (7.1) | 0.41% | — | Gitpython Project Gitpython | 25/8/2026 | 2/9/2026 | GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents… | |
| Analizada | Alta (8.7) | 0.65% | — | Gitpython Project Gitpython | 25/8/2026 | 2/9/2026 | GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled… | |
| Analizada | Crítica (9.3) | 0.78% | — | Gitpython Project Gitpython | 25/8/2026 | 2/9/2026 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write,… | |
| Analizada | Alta (8.6) | 0.18% | — | Gitpython Project Gitpython | 25/8/2026 | 2/9/2026 | GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is… | |
| Aplazada | Media (4.3) | 0.28% | — | Stratospheredigital WP Courses LMSAI | 25/8/2026 | 26/8/2026 | The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the 'resultID' parameter due to missing validation on a user controlled key. This makes it possible… | |
| Pendiente de análisis | Alta (7.1) | 0.26% | — | GitpythonAI | 25/8/2026 | 24/9/2026 | GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Unitedover DigitsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Privilege Escalation in Digits <= 9.2 versions. | |
| Analizada | Alta (8.8) | 0.77% | — | Gitlab | 23/8/2026 | 31/8/2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry. | |
| Pendiente de análisis | Alta (7.4) | 0.46% | — | GIT FOR WindowsAI | 21/8/2026 | 25/9/2026 | Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the… | |
| Pendiente de análisis | Media (6.5) | 0.48% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite initial redirect, and handle_remote_auth… | |
| Pendiente de análisis | Media (5.3) | 0.55% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in src/libgit2/delta.c trusts the attacker-controlled res_sz value parsed by hdr_sz from a delta object… | |
| Pendiente de análisis | Media (4.3) | 0.41% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from .gitmodules. The affected… | |
| Pendiente de análisis | Media (6.5) | 0.24% | — | Libgit2AI | 20/8/2026 | 9/9/2026 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD branch when… | |
| Analizada | Alta (8.4) | 0.42% | — | Gitpython Project Gitpython | 19/8/2026 | 2/9/2026 | GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during… | |
| Analizada | Alta (8.7) | 0.77% | — | Gitpython Project Gitpython | 19/8/2026 | 2/9/2026 | GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #'… | |
| Analizada | Alta (8.7) | 0.91% | — | Gitpython Project Gitpython | 19/8/2026 | 3/9/2026 | GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_from to emit a joined token parsed as… | |
| Analizada | Alta (7.2) | 0.54% | — | Gitpython Project Gitpython | 19/8/2026 | 3/9/2026 | GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to… | |
| Analizada | Alta (7.7) | 0.83% | — | Gitpython Project Gitpython | 19/8/2026 | 3/9/2026 | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository. | |
| Analizada | Alta (7.1) | 0.41% | — | Gitpython Project Gitpython | 19/8/2026 | 3/9/2026 | GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in… | |
| Aplazada | Media (6.9) | 0.46% | — | GITAIHome-assistant Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user… |