7.1
CVE-2026-73619
- EPSS 0.23%
- Veröffentlicht 13.08.2026 11:28:20
- Zuletzt bearbeitet 03.09.2026 16:10:08
- Erkennungen
GitPython before 3.1.57 Arbitrary File Read via Repo.archive()
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and include them in the returned archive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitpython Project ≫ Gitpython SwPlatform python Version < 3.1.57
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-539m-9xh6-q6rr
https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-archive