CVE-2026-87819
- EPSS 0.28%
- Veröffentlicht 09.09.2026 11:21:05
- Zuletzt bearbeitet 18.09.2026 18:17:34
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an untermi...
CVE-2026-87818
- EPSS 0.23%
- Veröffentlicht 09.09.2026 11:21:04
- Zuletzt bearbeitet 16.09.2026 15:12:45
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-de...
CVE-2026-87817
- EPSS 0.31%
- Veröffentlicht 09.09.2026 11:21:04
- Zuletzt bearbeitet 16.09.2026 15:24:41
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-c...
CVE-2026-78678
- EPSS 0.23%
- Veröffentlicht 25.08.2026 01:30:35
- Zuletzt bearbeitet 02.09.2026 18:17:58
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply r...
CVE-2026-78677
- EPSS 0.42%
- Veröffentlicht 25.08.2026 01:30:34
- Zuletzt bearbeitet 02.09.2026 19:12:24
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Rep...
CVE-2026-78676
- EPSS 0.4%
- Veröffentlicht 25.08.2026 01:30:33
- Zuletzt bearbeitet 02.09.2026 19:13:44
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that bec...
CVE-2026-78675
- EPSS 0.12%
- Veröffentlicht 25.08.2026 01:30:32
- Zuletzt bearbeitet 02.09.2026 19:26:24
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with incl...
CVE-2026-76221
- EPSS 0.37%
- Veröffentlicht 19.08.2026 14:17:48
- Zuletzt bearbeitet 02.09.2026 19:50:16
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers ca...
CVE-2026-76218
- EPSS 0.49%
- Veröffentlicht 19.08.2026 14:17:48
- Zuletzt bearbeitet 03.09.2026 15:03:14
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary...
CVE-2026-76219
- EPSS 0.28%
- Veröffentlicht 19.08.2026 14:17:48
- Zuletzt bearbeitet 03.09.2026 15:03:51
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or a...