GitPython是gitpython-developers开源的一个用于与 Git 存储库交互的 Python 库。 GitPython 3.1.48之前版本存在路径遍历漏洞,该漏洞源于在引用创建、重命名和删除操作中对引用路径验证不足,可能导致能够向使用GitPython的应用程序提供特制引用路径的攻击者在仓库.git目录外写入、覆盖、移动或删除文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gitpython-developers | GitPython | < 3.1.48 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gitpython-developers | GitPython | < 3.1.48 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42215 | 8.8 HIGH | GitPython: Command injection via Git options bypass |
| CVE-2026-42284 | 8.1 HIGH | GitPython: Unsafe option check validates multi_options before shlex.split transforms it |
| CVE-2026-44244 | 7.8 HIGH | GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath |
No comments yet