CVEs we hold for Gitpython-developers
Records whose assigning authority named Gitpython-developers as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-87818GitPython 3.1.59 Local File Content Oracle via --no-indexgitpython-developers GitPython
CVE-2026-87817GitPython before 3.1.60 Remote Code Execution via Git Directory Impersonationgitpython-developers GitPython
CVE-2026-78679GitPython before 3.1.59 Arbitrary File Read via TagReference.creategitpython-developers GitPython
CVE-2026-78678GitPython before 3.1.59 Arbitrary File Read via Repo.blame()gitpython-developers GitPython
CVE-2026-78677GitPython before 3.1.59 Path Traversal via separate-git-dirgitpython-developers GitPython
CVE-2026-78676GitPython before 3.1.59 Remote Code Execution via Config Injectiongitpython-developers GitPython
CVE-2026-78675GitPython before 3.1.59 Local File Content Disclosure via .gitmodulesgitpython-developers GitPython
CVE-2026-76222GitPython before 3.1.58 Path Traversal via .gitmodules Submodule Namegitpython-developers GitPython
CVE-2026-76221GitPython before 3.1.58 Config Injection via option-namegitpython-developers GitPython
CVE-2026-76220GitPython before 3.1.58 Command Execution via split_single_char_optionsgitpython-developers GitPython
CVE-2026-76219GitPython before 3.1.58 Arbitrary File Overwrite via read-treegitpython-developers GitPython
CVE-2026-76218GitPython before 3.1.58 Remote Code Execution via Repo.initgitpython-developers GitPython
CVE-2026-76217GitPython before 3.1.58 Arbitrary File Read via pathspec-from-filegitpython-developers GitPython
CVE-2026-73625GitPython before 3.1.54 Remote Code Execution via kwarg value smugglinggitpython-developers GitPython
CVE-2026-73624GitPython before 3.1.54 Arbitrary File Overwrite via diffgitpython-developers GitPython
CVE-2026-73623GitPython before 3.1.54 Remote Code Execution via --templategitpython-developers GitPython
CVE-2026-73622GitPython before 3.1.55 Environment Variable Exfiltration via Remote.add()gitpython-developers GitPython
CVE-2026-73621GitPython before 3.1.56 Arbitrary File Truncation via Commit.countgitpython-developers GitPython
CVE-2026-73620GitPython before 3.1.57 Arbitrary File Overwrite and Readgitpython-developers GitPython
CVE-2026-73619GitPython before 3.1.57 Arbitrary File Read via Repo.archive()gitpython-developers GitPython
CVE-2026-69097GitPython before 3.1.53 Config Injection via Submodule Namesgitpython-developers GitPython
CVE-2026-67326GitPython before 3.1.50 Newline Injection via config_writer sectiongitpython-developers GitPython
CVE-2026-67325GitPython before 3.1.51 Command Injection via option prefix abbreviationgitpython-developers GitPython
CVE-2026-67324GitPython 3.1.50 Authentication Bypass via Joined Short Optionsgitpython-developers GitPython
CVE-2026-67323GitPython before 3.1.51 Command Injection via unguarded Git optionsgitpython-developers GitPython
CVE-2026-67322GitPython before 3.1.52 Environment Variable Exfiltration via clone_fromgitpython-developers GitPython
CVE-2026-44244GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPathgitpython-developers GitPython
CVE-2026-44243GitPython: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repositorygitpython-developers GitPython
CVE-2026-42284GitPython: Unsafe option check validates multi_options before shlex.split transforms itgitpython-developers GitPython
CVE-2024-22190Untrusted search path under some conditions on Windows allows arbitrary code executiongitpython-developers GitPython
CVE-2023-40590Untrusted search path on Windows systems leading to arbitrary code executiongitpython-developers GitPython
34 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.