CVE-2026-73624

Source
https://cve.org/CVERecord?id=CVE-2026-73624
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73624.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73624
Aliases
Downstream
Published
2026-08-13T11:28:24.155Z
Modified
2026-08-15T11:48:07.639248139Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
GitPython before 3.1.54 Arbitrary File Overwrite via diff
Details

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwarg to write patch content to attacker-chosen file paths at process privilege level.

Database specific
{
    "cwe_ids": [
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73624.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/gitpython-developers/gitpython

Affected ranges

Type
GIT
Repo
https://github.com/gitpython-developers/gitpython
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.1.54"
        }
    ]
}

Affected versions

0.*
0.1.4
0.1.4-pre
0.1.5
0.1.6
0.2.0-beta1
0.3.0-beta1
0.3.0-beta2
0.3.1-beta1
0.3.1-beta2
0.3.2
0.3.2-RC1
0.3.2.1
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
1.*
1.0.0
1.0.1
1.0.2
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.8
2.1.9
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.20
3.1.22
3.1.23
3.1.24
3.1.25
3.1.26
3.1.27
3.1.28
3.1.29
3.1.3
3.1.30
3.1.31
3.1.32
3.1.33
3.1.34
3.1.35
3.1.38
3.1.4
3.1.40
3.1.41
3.1.42
3.1.43
3.1.44
3.1.47
3.1.48
3.1.49
3.1.5
3.1.50
3.1.51
3.1.52
3.1.53
3.1.6
3.1.7
3.1.8
3.1.9
Other
winerr_show

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73624.json"