gitpython-developers GitPython是gitpython-developers组织的一个封装版本控制功能的Python库。 gitpython-developers GitPython 3.1.56之前版本存在命令注入漏洞,该漏洞源于Commit.count()方法存在参数注入漏洞,该方法将关键字参数转发给'git rev-list'时缺少check_unsafe_options保护,可能导致攻击者通过控制output参数打开并截断目标文件为零字节,从而破坏或清空进程权限级别的任意
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gitpython-developers | GitPython | < 3.1.56 |
affected |
3.1.56 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gitpython-developers | GitPython | 0 ~ 3.1.56 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73625 | 8.8 HIGH | GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling |
| CVE-2026-73620 | 8.1 HIGH | GitPython before 3.1.57 Arbitrary File Overwrite and Read |
| CVE-2026-73624 | 8.1 HIGH | GitPython before 3.1.54 Arbitrary File Overwrite via diff |
| CVE-2026-73623 | 7.5 HIGH | GitPython before 3.1.54 Remote Code Execution via --template |
| CVE-2026-73622 | 7.5 HIGH | GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() |
| CVE-2026-73619 | 6.5 MEDIUM | GitPython before 3.1.57 Arbitrary File Read via Repo.archive() |
No comments yet