CVE-2026-76220
- EPSS 0.46%
- Veröffentlicht 19.08.2026 14:17:48
- Zuletzt bearbeitet 03.09.2026 15:04:15
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to ...
CVE-2026-76222
- EPSS 0.29%
- Veröffentlicht 19.08.2026 14:17:48
- Zuletzt bearbeitet 02.09.2026 19:37:05
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traver...
CVE-2026-76217
- EPSS 0.28%
- Veröffentlicht 19.08.2026 14:17:47
- Zuletzt bearbeitet 03.09.2026 15:01:08
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files acces...
CVE-2026-73625
- EPSS 0.5%
- Veröffentlicht 13.08.2026 11:28:24
- Zuletzt bearbeitet 03.09.2026 16:07:17
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg values. Attackers can supply crafted option dictionaries to c...
CVE-2026-73624
- EPSS 0.28%
- Veröffentlicht 13.08.2026 11:28:24
- Zuletzt bearbeitet 28.09.2026 18:42:29
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter or output kwar...
CVE-2026-73623
- EPSS 0.69%
- Veröffentlicht 13.08.2026 11:28:23
- Zuletzt bearbeitet 03.09.2026 16:09:20
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory cont...
CVE-2026-73621
- EPSS 0.2%
- Veröffentlicht 13.08.2026 11:28:22
- Zuletzt bearbeitet 03.09.2026 16:09:38
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can...
CVE-2026-73622
- EPSS 0.28%
- Veröffentlicht 13.08.2026 11:28:22
- Zuletzt bearbeitet 03.09.2026 16:09:30
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable references. Attackers can craft URLs with envi...
CVE-2026-73620
- EPSS 0.33%
- Veröffentlicht 13.08.2026 11:28:21
- Zuletzt bearbeitet 03.09.2026 16:09:53
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix to overwrite arbitrary files with repository content or -...
CVE-2026-73619
- EPSS 0.23%
- Veröffentlicht 13.08.2026 11:28:20
- Zuletzt bearbeitet 03.09.2026 16:10:08
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the filesystem and...