Security: gitpython-developers/GitPython
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksGHSA-6p8h-3wgx-97gf published
Jul 22, 2026 by ByronHigh -
Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)GHSA-fjr4-x663-mwxc published
Jul 22, 2026 by ByronHigh -
Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executionGHSA-r9mr-m37c-5fr3 published
Jul 22, 2026 by ByronHigh -
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)GHSA-3rp5-jjmw-4wv2 published
Jul 20, 2026 by ByronHigh -
Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLGHSA-rwj8-pgh3-r573 published
Jul 16, 2026 by ByronHigh -
command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`GHSA-956x-8gvw-wg5v published
Jul 12, 2026 by ByronHigh -
GitPython unsafe clone option gate bypass through joined short optionsGHSA-v396-v7q4-x2qj published
Jul 12, 2026 by ByronHigh -
Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklistGHSA-2f96-g7mh-g2hx published
Jul 12, 2026 by ByronHigh -
Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPathGHSA-mv93-w799-cj2w published
May 6, 2026 by ByronHigh -
Newline injection in config_writer().set_value() enables RCE via core.hooksPathGHSA-v87r-6q3f-2j67 published
Apr 29, 2026 by ByronHigh