Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GitPython — Vulnerabilities & Security Advisories 36

All 36 CVE vulnerabilities found in GitPython, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the software product GitPython, a Python library for interacting with Git repositories. The collection encompasses various weakness types, including code injection, path traversal, and improper input validation, covering advisories published from the library's initial release through recent updates. Readers can utilize this resource to track vendor-issued security advisories, understand the specific characteristics of common weakness classes within version control integration tools, and review the historical vulnerability landscape for this particular product. By consolidating data from multiple sources, the page provides a centralized view of security issues affecting GitPython, allowing developers and security professionals to assess risk exposure without navigating disparate databases. The entries reflect the evolution of security practices in Python-based Git clients, highlighting how specific implementation details have been targeted over time. This aggregation supports informed decision-making regarding patching priorities and dependency management for projects relying on GitPython functionality.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-100689 GitPython before 3.1.62 Path Traversal via gitmodules path CWE-22 5.9 Medium 2026-09-26
CVE-2026-87819 GitPython before 3.1.60 Denial of Service via ReDoS CWE-1333 7.5 High 2026-09-09
CVE-2026-87818 GitPython 3.1.59 Local File Content Oracle via --no-index CWE-88 6.5 Medium 2026-09-09
CVE-2026-87817 GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation CWE-94 8.8 High 2026-09-09
CVE-2026-78679 GitPython before 3.1.59 Arbitrary File Read via TagReference.create CWE-73 6.5 Medium 2026-08-25
CVE-2026-78678 GitPython before 3.1.59 Arbitrary File Read via Repo.blame() CWE-88 6.5 Medium 2026-08-25
CVE-2026-78677 GitPython before 3.1.59 Path Traversal via separate-git-dir CWE-22 7.5 High 2026-08-25
CVE-2026-78676 GitPython before 3.1.59 Remote Code Execution via Config Injection CWE-88 9.8 Critical 2026-08-25
CVE-2026-78675 GitPython before 3.1.59 Local File Content Disclosure via .gitmodules CWE-73 8.4 High 2026-08-25
CVE-2026-76222 GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name CWE-22 8.2 High 2026-08-19
CVE-2026-76221 GitPython before 3.1.58 Config Injection via option-name CWE-74 8.8 High 2026-08-19
CVE-2026-76220 GitPython before 3.1.58 Command Execution via split_single_char_options CWE-88 8.8 High 2026-08-19
CVE-2026-76218 GitPython before 3.1.58 Remote Code Execution via Repo.init CWE-88 7.5 High 2026-08-19
CVE-2026-76219 GitPython before 3.1.58 Arbitrary File Overwrite via read-tree CWE-88 8.1 High 2026-08-19
CVE-2026-76217 GitPython before 3.1.58 Arbitrary File Read via pathspec-from-file CWE-73 6.5 Medium 2026-08-19
CVE-2026-73625 GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling CWE-78 8.8 High 2026-08-13
CVE-2026-73624 GitPython before 3.1.54 Arbitrary File Overwrite via diff CWE-88 8.1 High 2026-08-13
CVE-2026-73622 GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() CWE-200 7.5 High 2026-08-13
CVE-2026-73623 GitPython before 3.1.54 Remote Code Execution via --template CWE-78 7.5 High 2026-08-13
CVE-2026-73621 GitPython before 3.1.56 Arbitrary File Truncation via Commit.count CWE-88 5.4 Medium 2026-08-13
CVE-2026-73619 GitPython before 3.1.57 Arbitrary File Read via Repo.archive() CWE-73 6.5 Medium 2026-08-13
CVE-2026-73620 GitPython before 3.1.57 Arbitrary File Overwrite and Read CWE-22 8.1 High 2026-08-13
CVE-2026-69097 GitPython before 3.1.53 Config Injection via Submodule Names CWE-74 7.0 High 2026-08-03
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options CWE-78 9.8 Critical 2026-08-01
CVE-2026-67323 GitPython before 3.1.51 Command Injection via unguarded Git options CWE-77 8.4 High 2026-08-01
CVE-2026-67326 GitPython before 3.1.50 Newline Injection via config_writer section CWE-20 7.0 High 2026-08-01
CVE-2026-67322 GitPython before 3.1.52 Environment Variable Exfiltration via clone_from CWE-200 7.5 High 2026-08-01
CVE-2026-67325 GitPython before 3.1.51 Command Injection via option prefix abbreviation CWE-78 8.8 High 2026-08-01
CVE-2026-44243 GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository CWE-22 8.1AI High AI 2026-05-07
CVE-2026-44244 GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath CWE-94 7.8 High 2026-05-07

All 36 known CVE vulnerabilities affecting GitPython with full Chinese analysis, references, and POCs where available.