gitpython-developers GitPython是gitpython-developers组织的一个封装版本控制功能的Python库。 gitpython-developers GitPython 3.1.57之前版本存在输入验证错误漏洞,该漏洞源于unsafe_git_archive_options防护中的黑名单不完整,遗漏了--add-file和--add-virtual-file选项,攻击者可通过Repo.archive()读取文件系统中的任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gitpython-developers | GitPython | < 3.1.57 |
affected |
3.1.57 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gitpython-developers | GitPython | 0 ~ 3.1.57 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73625 | 8.8 HIGH | GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling |
| CVE-2026-73620 | 8.1 HIGH | GitPython before 3.1.57 Arbitrary File Overwrite and Read |
| CVE-2026-73624 | 8.1 HIGH | GitPython before 3.1.54 Arbitrary File Overwrite via diff |
| CVE-2026-73623 | 7.5 HIGH | GitPython before 3.1.54 Remote Code Execution via --template |
| CVE-2026-73622 | 7.5 HIGH | GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() |
| CVE-2026-73621 | 5.4 MEDIUM | GitPython before 3.1.56 Arbitrary File Truncation via Commit.count |
No comments yet