Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

gitpython-developers — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting gitpython-developers. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GitPython-developers maintain a Python library for Git version control integration, primarily used by developers to automate repository operations. Historically, they've faced multiple remote code execution vulnerabilities through unsafe subprocess calls and path traversal issues, alongside cross-site scripting flaws in web interfaces. The project has documented seven CVEs, with several allowing arbitrary command execution via crafted repository paths or malicious Git operations. While no major public incidents are recorded, the consistent pattern of unsafe subprocess handling suggests ongoing security challenges. The library's widespread use in automation tools increases potential impact, though recent versions show improved input validation and sandboxing practices.

Top products by gitpython-developers: GitPython
CVE ID Title CVSS Severity Published
CVE-2026-87819 GitPython before 3.1.60 Denial of Service via ReDoS — GitPython CWE-1333 7.5 High 2026-09-09
CVE-2026-87818 GitPython 3.1.59 Local File Content Oracle via --no-index — GitPython CWE-88 6.5 Medium 2026-09-09
CVE-2026-87817 GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation — GitPython CWE-94 8.8 High 2026-09-09
CVE-2026-78679 GitPython before 3.1.59 Arbitrary File Read via TagReference.create — GitPython CWE-73 6.5 Medium 2026-08-25
CVE-2026-78678 GitPython before 3.1.59 Arbitrary File Read via Repo.blame() — GitPython CWE-88 6.5 Medium 2026-08-25
CVE-2026-78677 GitPython before 3.1.59 Path Traversal via separate-git-dir — GitPython CWE-22 7.5 High 2026-08-25
CVE-2026-78676 GitPython before 3.1.59 Remote Code Execution via Config Injection — GitPython CWE-88 9.8 Critical 2026-08-25
CVE-2026-78675 GitPython before 3.1.59 Local File Content Disclosure via .gitmodules — GitPython CWE-73 8.4 High 2026-08-25
CVE-2026-76222 GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name — GitPython CWE-22 8.2 High 2026-08-19
CVE-2026-76221 GitPython before 3.1.58 Config Injection via option-name — GitPython CWE-74 8.8 High 2026-08-19
CVE-2026-76220 GitPython before 3.1.58 Command Execution via split_single_char_options — GitPython CWE-88 8.8 High 2026-08-19
CVE-2026-76218 GitPython before 3.1.58 Remote Code Execution via Repo.init — GitPython CWE-88 7.5 High 2026-08-19
CVE-2026-76219 GitPython before 3.1.58 Arbitrary File Overwrite via read-tree — GitPython CWE-88 8.1 High 2026-08-19
CVE-2026-76217 GitPython before 3.1.58 Arbitrary File Read via pathspec-from-file — GitPython CWE-73 6.5 Medium 2026-08-19
CVE-2026-73625 GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling — GitPython CWE-78 8.8 High 2026-08-13
CVE-2026-73624 GitPython before 3.1.54 Arbitrary File Overwrite via diff — GitPython CWE-88 8.1 High 2026-08-13
CVE-2026-73622 GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add() — GitPython CWE-200 7.5 High 2026-08-13
CVE-2026-73623 GitPython before 3.1.54 Remote Code Execution via --template — GitPython CWE-78 7.5 High 2026-08-13
CVE-2026-73621 GitPython before 3.1.56 Arbitrary File Truncation via Commit.count — GitPython CWE-88 5.4 Medium 2026-08-13
CVE-2026-73619 GitPython before 3.1.57 Arbitrary File Read via Repo.archive() — GitPython CWE-73 6.5 Medium 2026-08-13
CVE-2026-73620 GitPython before 3.1.57 Arbitrary File Overwrite and Read — GitPython CWE-22 8.1 High 2026-08-13
CVE-2026-69097 GitPython before 3.1.53 Config Injection via Submodule Names — GitPython CWE-74 7.0 High 2026-08-03
CVE-2026-67323 GitPython before 3.1.51 Command Injection via unguarded Git options — GitPython CWE-77 8.4 High 2026-08-01
CVE-2026-67326 GitPython before 3.1.50 Newline Injection via config_writer section — GitPython CWE-20 7.0 High 2026-08-01
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options — GitPython CWE-78 9.8 Critical 2026-08-01
CVE-2026-67322 GitPython before 3.1.52 Environment Variable Exfiltration via clone_from — GitPython CWE-200 7.5 High 2026-08-01
CVE-2026-67325 GitPython before 3.1.51 Command Injection via option prefix abbreviation — GitPython CWE-78 8.8 High 2026-08-01
CVE-2026-44243 GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository — GitPython CWE-22 8.1AI High AI 2026-05-07
CVE-2026-44244 GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath — GitPython CWE-94 7.8 High 2026-05-07
CVE-2026-42284 GitPython: Unsafe option check validates multi_options before shlex.split transforms it — GitPython CWE-88 8.1 High 2026-05-07

This page lists every published CVE security advisory associated with gitpython-developers. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.