Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-59cr-6r3x-644w
  • PyPI/gitpython
GitPython submodule update path traversal can write outside the repository 3 days ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-g5vv-9gxw-82hx
  • PyPI/gitpython
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing 3 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-whh4-5q6c-9v3x
  • PyPI/gitpython
GitPython: --no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle 3 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-239g-whfq-7xj9
  • PyPI/gitpython
GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution 3 days ago
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3837
  • PyPI/gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3843
  • PyPI/gitpython
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution 10 Sep
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3841
  • PyPI/gitpython
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3840
  • PyPI/gitpython
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks 10 Sep
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3838
  • PyPI/gitpython
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite 10 Sep
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-3842
  • PyPI/gitpython
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL 10 Sep
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3839
  • PyPI/gitpython
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()` 10 Sep
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-3836
  • PyPI/gitpython
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist 10 Sep
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3984
  • PyPI/gitpython
See record for full details 09 Sep
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3982
  • PyPI/gitpython
See record for full details 09 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-3wxw-xv34-2frg
  • PyPI/gitpython
GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251) 08 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-8mcc-hrx5-hvxc
  • PyPI/gitpython
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination 08 Sep
  • Fix available
  • Severity - 8.7 (High)