Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-wvpp-8hx9-p66j
  • PyPI/gitpython
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution 07 Aug
  • Fix available
  • Severity - 8.8 (High)
GHSA-jm78-9fvv-mhgr
  • PyPI/gitpython
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE) 07 Aug
  • Fix available
  • Severity - 8.8 (High)
GHSA-hmq2-w58f-27jc
  • PyPI/gitpython
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython 07 Aug
  • Fix available
  • Severity - 8.2 (High)
GHSA-hh9p-6wh2-4mfc
  • PyPI/gitpython
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() 07 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-9rj7-rf2p-w77r
  • PyPI/gitpython
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks 07 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-4gmw-gg2m-w46p
  • PyPI/gitpython
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite 07 Aug
  • Fix available
  • Severity - 8.1 (High)
GHSA-p538-c434-8v24
  • PyPI/gitpython
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count 03 Aug
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-539m-9xh6-q6rr
  • PyPI/gitpython
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive() 03 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-3f7w-8rr8-f37f
  • PyPI/gitpython
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read 03 Aug
  • Fix available
  • Severity - 8.1 (High)
GHSA-94p4-4cq8-9g67
  • PyPI/gitpython
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573) 24 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-r9mr-m37c-5fr3
  • PyPI/gitpython
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution 24 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-6p8h-3wgx-97gf
  • PyPI/gitpython
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks 24 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-fjr4-x663-mwxc
  • PyPI/gitpython
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled) 24 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-3rp5-jjmw-4wv2
  • PyPI/gitpython
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE) 24 Jul
  • Fix available
  • Severity - 7.0 (High)
GHSA-rwj8-pgh3-r573
  • PyPI/gitpython
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL 21 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-956x-8gvw-wg5v
  • PyPI/gitpython
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()` 21 Jul
  • Fix available
  • Severity - 8.4 (High)