« Volver al listado

Gitpython Project

Gitpython Project Gitpython: vulnerabilidades y CVE

Gitpython Project Gitpython tiene 35 vulnerabilidades publicadas, 30 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE35
Últimos 12 meses30
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-87819Alta (8.7)0.52%—9 sept 2026
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed…
CVE-2026-87818Alta (7.1)0.41%—9 sept 2026
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with…
CVE-2026-87817Alta (8.7)0.40%—9 sept 2026
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary…
CVE-2026-78678Alta (7.1)0.41%—25 ago 2026
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to…
CVE-2026-78677Alta (8.7)0.65%—25 ago 2026
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir…
CVE-2026-78676Crítica (9.3)0.78%—25 ago 2026
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files…
CVE-2026-78675Alta (8.6)0.18%—25 ago 2026
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a…
CVE-2026-76222Alta (8.4)0.42%—19 ago 2026
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft…
CVE-2026-76221Alta (8.7)0.77%—19 ago 2026
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace…
CVE-2026-76220Alta (8.7)0.91%—19 ago 2026
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply…
CVE-2026-76219Alta (7.2)0.54%—19 ago 2026
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree…
CVE-2026-76218Alta (7.7)0.83%—19 ago 2026
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious…
CVE-2026-76217Alta (7.1)0.41%—19 ago 2026
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul…
CVE-2026-73625Alta (8.7)0.92%—13 ago 2026
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply…
CVE-2026-73624Alta (7.2)0.55%—13 ago 2026
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the…
CVE-2026-73623Alta (7.7)0.83%—13 ago 2026
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply…
CVE-2026-73622Alta (8.7)0.51%—13 ago 2026
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references.…
CVE-2026-73621Media (5.3)0.36%—13 ago 2026
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling…
CVE-2026-73620Alta (7.2)0.57%—13 ago 2026
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary…
CVE-2026-73619Alta (7.1)0.41%—13 ago 2026
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read…
CVE-2026-69097Alta (7.3)0.27%—3 ago 2026
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand…
CVE-2026-67326Alta (7.3)0.25%—1 ago 2026
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create…
CVE-2026-67325Alta (8.7)2.2%—1 ago 2026
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated…
CVE-2026-67324Crítica (9.3)0.64%—1 ago 2026
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced…
CVE-2026-67323Alta (8.6)1.3%—1 ago 2026
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to…
CVE-2026-67322Alta (8.7)0.33%—1 ago 2026
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls…
CVE-2026-44244Alta (7.8)0.22%—7 may 2026
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write()…
CVE-2026-44243Alta (7.8)0.44%—7 may 2026
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to…
CVE-2026-42284Crítica (9.8)0.71%—7 may 2026
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like…
CVE-2026-42215Alta (8.8)0.90%—7 may 2026
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the…