Gitpython Project Gitpython — known CVE vulnerabilities
Every CVE whose affected-product data names Gitpython Project Gitpython, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (35)
CVE-2026-67324 — CVSS 9.8 (critical): GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing…
CVE-2026-78676 — CVSS 9.8 (critical): GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values…
CVE-2023-40267 — CVSS 9.8 (critical): GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete…
CVE-2026-42215 — CVSS 8.8 (high): GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks…
CVE-2026-67325 — CVSS 8.8 (high): GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation…
CVE-2026-87817 — CVSS 8.8 (high): GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using…
CVE-2026-76220 — CVSS 8.8 (high): GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a…
CVE-2026-76221 — CVSS 8.8 (high): GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge…
CVE-2026-73625 — CVSS 8.8 (high): GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by…
CVE-2026-67323 — CVSS 8.4 (high): GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote()…
CVE-2026-78675 — CVSS 8.4 (high): GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by…
CVE-2026-76222 — CVSS 8.2 (high): GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at…
CVE-2022-24439 — CVSS 8.1 (high): All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it…
CVE-2026-76219 — CVSS 8.1 (high): GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and…
CVE-2026-42284 — CVSS 8.1 (high): GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the…
CVE-2026-73620 — CVSS 8.1 (high): GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass…
CVE-2026-73624 — CVSS 8.1 (high): GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git…
CVE-2024-22190 — CVSS 7.8 (high): GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On Windows, GitPython…
CVE-2026-44244 — CVSS 7.8 (high): GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to…
CVE-2023-40590 — CVSS 7.8 (high): GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working…
CVE-2026-87819 — CVSS 7.5 (high): GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit…
CVE-2026-67322 — CVSS 7.5 (high): GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed…
CVE-2026-73622 — CVSS 7.5 (high): GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing…
CVE-2026-73623 — CVSS 7.5 (high): GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve…
CVE-2026-76218 — CVSS 7.5 (high): GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation…
CVE-2026-78677 — CVSS 7.5 (high): GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories…
CVE-2026-44243 — CVSS 7.1 (high): GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows…
CVE-2026-69097 — CVSS 7.0 (high): GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration…
CVE-2026-67326 — CVSS 7.0 (high): GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject…
CVE-2026-87818 — CVSS 6.5 (medium): GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths…
CVE-2026-76217 — CVSS 6.5 (medium): GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and…
CVE-2026-78678 — CVSS 6.5 (medium): GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S…
CVE-2026-73619 — CVSS 6.5 (medium): GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and…
CVE-2026-73621 — CVSS 5.4 (medium): GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git…
CVE-2023-41040 — CVSS 4.0 (medium): GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython reads files from…