CVE-2023-40590
CVE-2023-40590 is a high-severity vulnerability in Gitpython Project Gitpython with a CVSS 3.x base score of 7.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-426.
Key facts
- Severity: High (CVSS 3.x base score 7.8)
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-426
- Affected product: Gitpython Project Gitpython
- Published:
- Last modified:
Description
GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`. This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo. An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands. There is no fix currently available for windows users, however there are a few mitigations. 1: Default to an absolute path for the git program on Windows, like `C:\\Program Files\\Git\\cmd\\git.EXE` (default git path installation). 2: Require users to set the `GIT_PYTHON_GIT_EXECUTABLE` environment variable on Windows systems. 3: Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the `GIT_PYTHON_GIT_EXECUTABLE` env var to an absolute path. 4: Resolve the executable manually by only looking into the `PATH` environment variable.
Frequently asked questions
- What is CVE-2023-40590?
- GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a `git.exe` or `git` executable, that program will be run instead of the one in the user's `PATH`. This is more of a problem on how Python interacts with Windows systems, Linux and any other OS aren't affected by this. But probably people using GitPython usually run it from the CWD of a repo. An attacker can trick a user to download a repository with a malicious `git` executable, if the user runs/imports GitPython from that directory, it allows the attacker to run any arbitrary commands. There is no fix currently available for windows users, however there are a few mitigations. 1: Default to an absolute path for the git program on Windows, like `C:\\Program Files\\Git\\cmd\\git.EXE` (default git path installation). 2: Require users to set the `GIT_PYTHON_GIT_EXECUTABLE` environment variable on Windows systems. 3: Make this problem prominent in the documentation and advise users to never run GitPython from an untrusted repo, or set the `GIT_PYTHON_GIT_EXECUTABLE` env var to an absolute path. 4: Resolve the executable manually by only looking into the `PATH` environment variable.
- How severe is CVE-2023-40590?
- CVE-2023-40590 has a CVSS 3.x base score of 7.8, rated high severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2023-40590 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-40590?
- CVE-2023-40590 affects Gitpython Project Gitpython. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-40590?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2023-40590 published?
- CVE-2023-40590 was published on 2023-08-28 and last updated on 2026-06-17.
References
- https://docs.python.org/3/library/subprocess.html#popen-constructor
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wfm5-v35h-vwf4
Affected products (1)
- cpe:2.3:a:gitpython_project:gitpython:*:*:*:*:*:python:*:*
More vulnerabilities in Gitpython Project Gitpython
- CVE-2026-78676 — Critical (CVSS 9.8): GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting…
- CVE-2026-67324 — Critical (CVSS 9.8): GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of…
- CVE-2023-40267 — Critical (CVSS 9.8): GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists…
- CVE-2026-87817 — High (CVSS 8.8): GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the…
- CVE-2026-76221 — High (CVSS 8.8): GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows…
- CVE-2026-76220 — High (CVSS 8.8): GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be…
All CVEs affecting Gitpython Project Gitpython →
Other CWE-426 (Untrusted Search Path) vulnerabilities
- CVE-2026-78155 — Critical (CVSS 9.9): privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator…
- CVE-2026-74872 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash…
- CVE-2026-45772 — Critical (CVSS 9.8): Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14,…
- CVE-2025-26155 — Critical (CVSS 9.8): NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path…
- CVE-2024-53866 — Critical (CVSS 9.8): The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one…
- CVE-2024-38462 — Critical (CVSS 9.8): iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the…
Browse all CWE-426 (Untrusted Search Path) vulnerabilities →