gitpython_project / gitpython
25 known vulnerabilities in gitpython_project gitpython.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-78676 | High | 0.4% | 9.8 | GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value… | |
| CVE-2026-67324 | High | 0.4% | 9.8 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> … | |
| CVE-2026-67325 | Medium | 1.9% | 8.8 | GitPython before 3.1.51 contains an incomplete command injection blocklist that … | |
| CVE-2026-67323 | Medium | 1.0% | 8.4 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as k… | |
| CVE-2026-73623 | Medium | 1.0% | 7.5 | GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_opti… | |
| CVE-2026-76218 | Medium | 0.7% | 7.5 | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.i… | |
| CVE-2026-73625 | Medium | 0.7% | 8.8 | GitPython versions before 3.1.54 contain a remote code execution vulnerability i… | |
| CVE-2026-76220 | Medium | 0.6% | 8.8 | GitPython before 3.1.58 contains a command execution vulnerability in the check_… | |
| CVE-2026-76221 | Medium | 0.5% | 8.8 | GitPython before 3.1.58 contains a config-name injection vulnerability in the op… | |
| CVE-2026-78677 | Medium | 0.4% | 7.5 | GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, … | |
| CVE-2026-73620 | Medium | 0.4% | 8.1 | GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checko… | |
| CVE-2026-73622 | Medium | 0.4% | 7.5 | GitPython before 3.1.55 fails to disable environment variable expansion in Remot… | |
| CVE-2026-76222 | Medium | 0.3% | 8.2 | GitPython before 3.1.58 fails to validate submodule names from .gitmodules files… | |
| CVE-2026-87817 | Medium | 0.3% | 8.8 | GitPython before 3.1.60 fails to properly validate the git directory location, a… | |
| CVE-2026-76219 | Medium | 0.3% | 8.1 | GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerabili… | |
| CVE-2026-87819 | Medium | 0.3% | 7.5 | GitPython before 3.1.60 contains a regular expression denial of service vulnerab… | |
| CVE-2026-67326 | Medium | 0.3% | 7.0 | GitPython before 3.1.50 fails to validate newline characters in the section para… | |
| CVE-2026-67322 | Medium | 0.3% | 7.5 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Re… | |
| CVE-2026-69097 | Medium | 0.3% | 7.0 | GitPython before 3.1.53 fails to properly escape section names in git config fil… | |
| CVE-2026-78675 | Medium | 0.1% | 8.4 | GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules… | |
| CVE-2026-76217 | Low | 0.4% | 6.5 | GitPython versions before 3.1.58 fail to validate options passed to git rm and g… | |
| CVE-2026-73619 | Low | 0.3% | 6.5 | GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archiv… | |
| CVE-2026-78678 | Low | 0.2% | 6.5 | GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_gi… | |
| CVE-2026-87818 | Low | 0.2% | 6.5 | GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff … | |
| CVE-2026-73621 | Low | 0.2% | 5.4 | GitPython before 3.1.56 contains an argument injection vulnerability in the Comm… |