Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

gitpython-developers — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting gitpython-developers. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GitPython-developers maintain a Python library for Git version control integration, primarily used by developers to automate repository operations. Historically, they've faced multiple remote code execution vulnerabilities through unsafe subprocess calls and path traversal issues, alongside cross-site scripting flaws in web interfaces. The project has documented seven CVEs, with several allowing arbitrary command execution via crafted repository paths or malicious Git operations. While no major public incidents are recorded, the consistent pattern of unsafe subprocess handling suggests ongoing security challenges. The library's widespread use in automation tools increases potential impact, though recent versions show improved input validation and sandboxing practices.

Found 13 results / 13Clear Filters
Top products by gitpython-developers: GitPython
CVE IDTitleCVSSSeverityPublished
CVE-2026-69097 GitPython before 3.1.53 Config Injection via Submodule Names — GitPythonCWE-74 7.0 High2026-08-03
CVE-2026-67323 GitPython before 3.1.51 Command Injection via unguarded Git options — GitPythonCWE-77 8.4 High2026-08-01
CVE-2026-67324 GitPython 3.1.50 Authentication Bypass via Joined Short Options — GitPythonCWE-78 9.8 Critical2026-08-01
CVE-2026-67326 GitPython before 3.1.50 Newline Injection via config_writer section — GitPythonCWE-20 7.0 High2026-08-01
CVE-2026-67325 GitPython before 3.1.51 Command Injection via option prefix abbreviation — GitPythonCWE-78 8.8 High2026-08-01
CVE-2026-67322 GitPython before 3.1.52 Environment Variable Exfiltration via clone_from — GitPythonCWE-200 7.5 High2026-08-01
CVE-2026-44243 GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository — GitPythonCWE-22 8.1AIHighAI2026-05-07
CVE-2026-44244 GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath — GitPythonCWE-94 7.8 High2026-05-07
CVE-2026-42284 GitPython: Unsafe option check validates multi_options before shlex.split transforms it — GitPythonCWE-88 8.1 High2026-05-07
CVE-2026-42215 GitPython: Command injection via Git options bypass — GitPythonCWE-78 8.8 High2026-05-07
CVE-2024-22190 Untrusted search path under some conditions on Windows allows arbitrary code execution — GitPythonCWE-426 7.8 High2024-01-11
CVE-2023-41040 GitPython blind local file inclusion — GitPythonCWE-22 4.0 Medium2023-08-30
CVE-2023-40590 Untrusted search path on Windows systems leading to arbitrary code execution — GitPythonCWE-426 7.8 High2023-08-28

This page lists every published CVE security advisory associated with gitpython-developers. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.