VendorsGitPython Projectgitpythonall versions
Vulnerabilities

GitPython Project GitPython

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

34CVEs
CVE-2022-24439
Remote Code Execution (RCE)
Published 2022-12-12 · Modified
9.8EPSS 0.057
CVE-2023-40267
GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
Published 2023-08-11 · Modified
9.8EPSS 0.012
CVE-2026-42284
GitPython: Unsafe option check validates multi_options before shlex.split transforms it
Published 2026-05-07 · Modified
9.8EPSS 0.006
CVE-2026-78676
GitPython before 3.1.59 Remote Code Execution via Config Injection
Published 2026-08-25 · Analyzed
9.8EPSS 0.004
CVE-2026-67324
GitPython 3.1.50 Authentication Bypass via Joined Short Options
Published 2026-08-01 · Analyzed
9.8EPSS 0.004
CVE-2026-67325
GitPython before 3.1.51 Command Injection via option prefix abbreviation
Published 2026-08-01 · Analyzed
8.8EPSS 0.019
CVE-2026-73623
GitPython before 3.1.54 Remote Code Execution via --template
Published 2026-08-13 · Analyzed
8.8EPSS 0.010
CVE-2026-42215
GitPython: Command injection via Git options bypass
Published 2026-05-07 · Analyzed
8.8EPSS 0.007
CVE-2026-76218
GitPython before 3.1.58 Remote Code Execution via Repo.init
Published 2026-08-19 · Analyzed
8.8EPSS 0.007
CVE-2026-73625
GitPython before 3.1.54 Remote Code Execution via kwarg value smuggling
Published 2026-08-13 · Analyzed
8.8EPSS 0.007
CVE-2026-76220
GitPython before 3.1.58 Command Execution via split_single_char_options
Published 2026-08-19 · Analyzed
8.8EPSS 0.006
CVE-2026-76221
GitPython before 3.1.58 Config Injection via option-name
Published 2026-08-19 · Analyzed
8.8EPSS 0.005
CVE-2026-87817
GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonation
Published 2026-09-09 · Analyzed
8.8EPSS 0.003
CVE-2026-78677
GitPython before 3.1.59 Path Traversal via separate-git-dir
Published 2026-08-25 · Analyzed
8.7EPSS 0.004
CVE-2026-73622
GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()
Published 2026-08-13 · Analyzed
8.7EPSS 0.004
CVE-2026-87819
GitPython before 3.1.60 Denial of Service via ReDoS
Published 2026-09-09 · Analyzed
8.7EPSS 0.003
CVE-2026-67322
GitPython before 3.1.52 Environment Variable Exfiltration via clone_from
Published 2026-08-01 · Analyzed
8.7EPSS 0.003
CVE-2026-67323
GitPython before 3.1.51 Command Injection via unguarded Git options
Published 2026-08-01 · Analyzed
8.6EPSS 0.010
CVE-2026-78675
GitPython before 3.1.59 Local File Content Disclosure via .gitmodules
Published 2026-08-25 · Analyzed
8.6EPSS 0.001
CVE-2026-76222
GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Name
Published 2026-08-19 · Analyzed
8.4EPSS 0.003
CVE-2026-73620
GitPython before 3.1.57 Arbitrary File Overwrite and Read
Published 2026-08-13 · Analyzed
8.1EPSS 0.004
CVE-2026-76219
GitPython before 3.1.58 Arbitrary File Overwrite via read-tree
Published 2026-08-19 · Analyzed
8.1EPSS 0.003
CVE-2023-40590
Untrusted search path on Windows systems leading to arbitrary code execution
Published 2023-08-28 · Modified
7.8EPSS 0.005
CVE-2026-44243
GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository
Published 2026-05-07 · Analyzed
7.8EPSS 0.004
CVE-2024-22190
Untrusted search path under some conditions on Windows allows arbitrary code execution
Published 2024-01-11 · Modified
7.8EPSS 0.003
CVE-2026-67326
GitPython before 3.1.50 Newline Injection via config_writer section
Published 2026-08-01 · Analyzed
7.8EPSS 0.003
CVE-2026-44244
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
Published 2026-05-07 · Analyzed
7.8EPSS 0.002
CVE-2026-69097
GitPython before 3.1.53 Config Injection via Submodule Names
Published 2026-08-03 · Analyzed
7.3EPSS 0.003
CVE-2026-76217
GitPython before 3.1.58 Arbitrary File Read via pathspec-from-file
Published 2026-08-19 · Analyzed
7.1EPSS 0.004
CVE-2026-73619
GitPython before 3.1.57 Arbitrary File Read via Repo.archive()
Published 2026-08-13 · Analyzed
7.1EPSS 0.003
CVE-2026-78678
GitPython before 3.1.59 Arbitrary File Read via Repo.blame()
Published 2026-08-25 · Analyzed
7.1EPSS 0.002
CVE-2026-87818
GitPython 3.1.59 Local File Content Oracle via --no-index
Published 2026-09-09 · Analyzed
7.1EPSS 0.002
CVE-2023-41040
GitPython blind local file inclusion
Published 2023-08-30 · Modified
6.5EPSS 0.011
CVE-2026-73621
GitPython before 3.1.56 Arbitrary File Truncation via Commit.count
Published 2026-08-13 · Analyzed
5.4EPSS 0.002